logo

Microsoft's Zero-Day Legal Threats Spark Backlash

ID: b8876426-e540-5289-bd62-59125754cec9

STIX ID: report--b8876426-e540-5289-bd62-59125754cec9

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-06-01

Date Updated: 2026-06-15

Author: Rob Wright

...
...

Microsoft was criticized after an anonymous researcher known as "Nightmare-Eclipse" published multiple zero-day vulnerabilities and PoC exploits (including BlueHammer/CVE-2026-33825, RedSun, Undefend, YellowKey, GreenPlasma, MiniPlasma) that were reportedly exploited in the wild; MSRC's initial blog post threatening criminal prosecution prompted broad backlash from the security community and was later softened, while the researcher signaled potential further drops and other researchers reportedly contributed vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.