discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump

Microsoft says six Windows zero-days were disclosed outside its channels as a researcher vows another exploit dump on July 14 after escalating conflict.

By Jessica Lyons·May 28·theregister.com·2 min read

Intelligence analysis by GPT-5.4 Mini

The Register reports a public split between Microsoft and a researcher known as Nightmare Eclipse, who has already released six Windows zero-days. Microsoft says the bugs were not reported through its channels; the researcher says Microsoft humiliated them and is blocking further disclosure.

Why it matters

Three of the six flaws are already being exploited, and one more has no fix yet. The dispute shows how disclosure breakdowns can turn into immediate enterprise risk, with defenders losing time to patch.

A computer researcher found several weak spots in Windows, like loose boards in a fence. Instead of quietly helping fix them, the fight with Microsoft got loud and angry, and some of the weak spots were shown to everyone.

That matters because bad people can copy the weak spots and use them before the holes are patched. It is like leaving a broken lock on a door while telling the whole neighborhood where the key is missing.

The article says one more big release may come on July 14. That is why security teams are paying attention now: they may need to fix problems fast before more attackers rush in.

Analysis

What happened

The article describes an escalating fight between Microsoft and a bug hunter operating under the names Nightmare Eclipse and Chaotic Eclipse. The researcher has already published six Windows zero-days: RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma. Microsoft says none of them were submitted through its official reporting channels before becoming public.

The company says attackers quickly started using three of the bugs after the researcher posted working proof-of-concept code on now-banned GitHub and GitLab accounts. Those three are BlueHammer, RedSun, and UnDefend. Microsoft also says YellowKey, tracked as CVE-2026-45585, is more likely to be exploited because a working proof of concept exists, while GreenPlasma and MiniPlasma still have no fixes.

Why the dispute matters

Microsoft responded with a blog post criticizing uncoordinated disclosure and warning that its Digital Crimes Unit will continue pursuing actors that enable criminal activity. The post did not answer The Register's questions about whether Microsoft plans legal action, whether Nightmare is a current or former employee, or whether the researcher's MSRC account was removed.

Nightmare says Microsoft deleted the account used to report bugs, refused to communicate, and publicly embarrassed them. They also say they are being blocked from releasing more material for now, but promised another major drop on July 14.

Security commentators in the story say the real damage is already visible. Dustin Childs of Zero Day Initiative says Microsoft could have handled the situation better and given customers clearer guidance. Katie Moussouris says Microsoft's language sends mixed signals and does not help calm things down. The bigger takeaway is that the gap between disclosure and weaponization can now be extremely short, which leaves defenders very little time to react.

Key points

  • Microsoft says six Windows zero-days were made public without being reported through its official channels first.
  • Three of the flaws were reportedly attacked soon after proof-of-concept code appeared online.
  • YellowKey, also known as CVE-2026-45585, is considered more likely to be exploited because a working proof of concept exists.
  • The researcher says Microsoft deleted the account used for reporting bugs and treated them badly.
  • Microsoft says its Digital Crimes Unit will keep pursuing actors that enable criminal activity.

Originally reported at

theregister.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityresearchpolicyethicstech

Author

Jessica Lyons

Intelligence analysis by

GPT-5.4 Mini

Published

May 28, 2026

Source

theregister.com

Share

Topics

securityresearchpolicyethicstech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…