Drooid Logo
Back to story perspectives

Full Breakdown

Microsoft Threatens Legal Action Over Uncoordinated Zero-Day Disclosures by Researcher Nightmare Eclipse

5/31/2026, 8:22:31 PM

Uncoordinated Zero-Day Disclosures Spark Corporate Threats

In early May 2026, security researcher “Nightmare Eclipse” posted proof-of-concept code for six unknown Windows vulnerabilities on GitHub and GitLab. Microsoft’s MSRC blog warned the disclosures violated its coordinated-vulnerability-disclosure policy and that its Digital Crimes Unit could pursue criminal action against the researcher and any exploiters.

Background: Coordinated Disclosure Policy

Microsoft runs a bug-bounty program that rewards private reports via the Microsoft Security Response Center (MSRC). It urges researchers to share findings before public release, saying uncoordinated disclosures put customers at “unnecessary risk.”

Key Players

The dispute pits Microsoft (Digital Crimes Unit and MSRC) against researcher Nightmare Eclipse, Microsoft analyst Kevin Beaumont, Luta Security founder Katie Moussouris, and U.S. agency CISA, which listed three flaws in its Known Exploited Vulnerabilities catalog.

Data & Statistics

The six flaws—BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma and MiniPlasma—enable local-privilege escalation or BitLocker bypass; three (BlueHammer, RedSun, UnDefend) were seen in wild attacks, prompting emergency patches and CISA listings.

Official Statements & Responses

Microsoft’s MSRC blog said vulnerabilities “were not responsibly disclosed,” security teams were “working around the clock to understand the impact, protect customers, and develop updates,” and Digital Crimes Unit “will continue bringing cases against actors and those that enable criminal activity – coordinating as needed with law enforcement worldwide.”

Criticism & Opposition

Nightmare Eclipse claims mistreatment, a denied bounty, and bans that pushed release. Microsoft analyst Kevin Beaumont labeled threat to criminalize reporting “hypocrisy” and warned that “proof-of-concept exploit creation and distribution for zero-days is ‘criminal activity’ now?” Katie Moussouris warned Digital Crimes Unit’s stance could cause a “chilling effect,” eroding trust and discouraging disclosures.

Conflicting Reports & Gaps

TechCrunch reports three of the six flaws were used in real-world attacks; The Hacker News describes “several” exploits, creating a discrepancy on scope. CVE identifiers for GreenPlasma and MiniPlasma are absent, leaving severity unclear. The researcher’s claim of a personal threat from Microsoft remains unverified.

Verbatim Quotes

  • “The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed.” — Microsoft, MSRC blog
  • “Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity — coordinating as needed with law enforcement around the world,” — Microsoft
  • “ "If Microsoft’s tactic is to try to criminalise not following often arbitrary “responsible disclosure” frameworks, good luck defending that in court.” — Kevin Beaumont, DoublePulsar.com
  • “Invoking the term ‘responsible’ disclosure was the first strike in my book,” — Katie Moussouris, Luta Security

What’s Next

Nightmare Eclipse announced a further disclosure for July 14 2026, while Microsoft signaled possible criminal complaints through its Digital Crimes Unit. The clash has revived calls for U.S. legislation on coordinated vulnerability disclosure and clearer industry guidelines to balance researcher incentives with user safety.