Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump
Microsoft says six Windows zero-days were disclosed outside its channels as a researcher vows another exploit dump on July 14 after escalating conflict.
Intelligence analysis by GPT-5.4 Mini
The Register reports a public split between Microsoft and a researcher known as Nightmare Eclipse, who has already released six Windows zero-days. Microsoft says the bugs were not reported through its channels; the researcher says Microsoft humiliated them and is blocking further disclosure.
A computer researcher found several weak spots in Windows, like loose boards in a fence. Instead of quietly helping fix them, the fight with Microsoft got loud and angry, and some of the weak spots were shown to everyone.
That matters because bad people can copy the weak spots and use them before the holes are patched. It is like leaving a broken lock on a door while telling the whole neighborhood where the key is missing.
The article says one more big release may come on July 14. That is why security teams are paying attention now: they may need to fix problems fast before more attackers rush in.
Analysis
What happened
The article describes an escalating fight between Microsoft and a bug hunter operating under the names Nightmare Eclipse and Chaotic Eclipse. The researcher has already published six Windows zero-days: RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma. Microsoft says none of them were submitted through its official reporting channels before becoming public.
The company says attackers quickly started using three of the bugs after the researcher posted working proof-of-concept code on now-banned GitHub and GitLab accounts. Those three are BlueHammer, RedSun, and UnDefend. Microsoft also says YellowKey, tracked as CVE-2026-45585, is more likely to be exploited because a working proof of concept exists, while GreenPlasma and MiniPlasma still have no fixes.
Why the dispute matters
Microsoft responded with a blog post criticizing uncoordinated disclosure and warning that its Digital Crimes Unit will continue pursuing actors that enable criminal activity. The post did not answer The Register's questions about whether Microsoft plans legal action, whether Nightmare is a current or former employee, or whether the researcher's MSRC account was removed.
Nightmare says Microsoft deleted the account used to report bugs, refused to communicate, and publicly embarrassed them. They also say they are being blocked from releasing more material for now, but promised another major drop on July 14.
Security commentators in the story say the real damage is already visible. Dustin Childs of Zero Day Initiative says Microsoft could have handled the situation better and given customers clearer guidance. Katie Moussouris says Microsoft's language sends mixed signals and does not help calm things down. The bigger takeaway is that the gap between disclosure and weaponization can now be extremely short, which leaves defenders very little time to react.
Key points
- Microsoft says six Windows zero-days were made public without being reported through its official channels first.
- Three of the flaws were reportedly attacked soon after proof-of-concept code appeared online.
- YellowKey, also known as CVE-2026-45585, is considered more likely to be exploited because a working proof of concept exists.
- The researcher says Microsoft deleted the account used for reporting bugs and treated them badly.
- Microsoft says its Digital Crimes Unit will keep pursuing actors that enable criminal activity.



