logo

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

ID: 30399ca3-15f3-5e66-93fc-a6076841d65f

STIX ID: report--30399ca3-15f3-5e66-93fc-a6076841d65f

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

Author: [email protected] (The Hacker News)

...
...

Microsoft criticized an uncoordinated disclosure by researcher 'Chaotic Eclipse' (aka Nightmare-Eclipse) who published multiple zero-day vulnerabilities affecting Windows components (including Defender and BitLocker) — several CVEs are listed (BlueHammer CVE-2026-33825, RedSun CVE-2026-41091, UnDefend CVE-2026-45498, YellowKey CVE-2026-45585, GreenPlasma, MiniPlasma). The report states BlueHammer, RedSun, and UnDefend are being actively exploited in the wild, proof-of-concept exploit code was posted publicly (subsequently removed/blocked on platforms), and the researcher has publicly threatened an additional release on July 14, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.