Microsoft’s Zero-Day Feud With Rogue Researcher Spirals Toward July Deadline

A researcher known as Nightmare Eclipse has released six Windows zero-days since April, with three under active exploitation. After account bans and public accusations of mistreatment, the bug hunter threatens a major disclosure on July 14. Microsoft condemns the uncoordinated releases and signals law enforcement involvement. The feud highlights deep cracks in vulnerability disclosure practices.
Microsoft’s Zero-Day Feud With Rogue Researcher Spirals Toward July Deadline
Written by Emma Rogers

A lone Windows expert has dropped six zero-days in quick succession. Three reached active exploitation almost immediately. Now the researcher promises something far bigger on July 14. Microsoft calls the releases unjustifiable. The company has turned to its Digital Crimes Unit and law enforcement. The clash exposes raw tensions in how big tech handles outside bug reports.

Nightmare Eclipse, who also posts as Chaotic Eclipse and Dead Eclipse, began releasing proof-of-concept code in early April 2026. The flaws targeted Windows Defender, BitLocker, and local privilege escalation paths. Barracuda Networks detailed the list on May 19. BlueHammer, tracked as CVE-2026-33825, let attackers jump from user to SYSTEM on Defender. It was later patched yet saw real-world use. RedSun and UnDefend followed similar patterns. YellowKey bypassed BitLocker protections on TPM-only drives. GreenPlasma and MiniPlasma offered additional local elevation techniques. Three of the six remain without fixes. Microsoft has rated exploitation more likely for YellowKey, also known as CVE-2026-45585.

But the technical details tell only part of the story. The researcher claims a broken relationship with Microsoft Security Response Center staff. Accounts were deleted. Communication stopped. No bounty arrived despite reports. “You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot,” the researcher wrote on a personal blog. Another post accused Microsoft of humiliation and insults. “Mark this date July 14th, I will make sure your bones are shattered that day.”

Microsoft rejects the narrative. In a blog post timed to the latest escalation, the company stressed coordinated vulnerability disclosure. None of the flaws reached it through official channels before public release, Redmond said. “Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences,” the statement read. Security teams worked around the clock on mitigations. The Digital Crimes Unit would pursue cases against actors and those enabling them, coordinating with law enforcement worldwide. The Hacker News covered the Microsoft position on May 28.

GitHub banned the researcher’s account. Repositories moved to GitLab, which soon suspended access too. The researcher kept posting signed statements. Some observers see a former insider. Deep knowledge of the Windows codebase fuels that speculation, though no confirmation exists. Personal grievance drives the campaign, according to multiple analyses. The researcher has spoken of agreements broken, homelessness, and threats from MSRC personnel. “I was told personally by them that they will ruin my life and they did,” one post claimed.

Attacks followed fast. Huntress and other firms spotted intrusions using the fresh code. Russian-geolocated infrastructure appeared in some chains. Enterprises faced sudden risk. BlueHammer turned Defender against itself in certain configurations. YellowKey undermined BitLocker recovery protections for physically accessible machines. Defenders scrambled to layer controls while patches lagged.

The cybersecurity community split in reaction. Some researchers aired their own sour experiences with Microsoft’s disclosure process. Others condemned public zero-days outright. Kevin Beaumont questioned the legal threat. “If Microsoft’s tactic is to try to criminalize not following often arbitrary ‘responsible disclosure’ frameworks, good luck defending that in court,” he noted in commentary referenced across reports. Katie Moussouris and Dustin Childs weighed in on the two-way street of coordinated disclosure. The episode, they suggested, damages trust on all sides.

Microsoft has patched some flaws in subsequent updates. Others linger. YellowKey, GreenPlasma, and MiniPlasma still await resolution as of late May. The company advises immediate updates to Defender signatures and hardened configurations for BitLocker. Yet the researcher’s next move looms. A “bone shattering” release is threatened for mid-July. Documents held in reserve could surface then. The researcher says Microsoft still controls certain chains that prevent earlier drops.

This isn’t the first time a disgruntled finder has gone public. It stands out for volume, speed, and personal animus. Past disputes usually involved single bugs or payment disagreements. Here the releases form a sustained barrage. Each new proof-of-concept raises the bar for what counts as responsible. Attackers don’t wait for Patch Tuesday when code appears on GitHub first.

And the stakes climb. Windows runs on hundreds of millions of enterprise desktops. Defender protects many of them. Local privilege escalation flaws chain easily with other bugs for full compromise. BitLocker bypasses threaten data at rest. Three confirmed active exploits already demonstrate the speed of adoption. A fresh dump in July could accelerate that further.

Microsoft insists its process works when followed. Bounty programs and Zero Day Quest events aim to channel research productively. Researchers counter that arbitrary policies, deleted accounts, and public shaming deter participation. One veteran told PCMag the interaction left “such a bad taste” that further engagement felt pointless. Another said Microsoft made reporting less attractive, then issued a blog about shared responsibility. “That’s a CYA, not a bug program,” the commenter added.

So far no lawsuit has materialized. Legal threats remain in the background. The Digital Crimes Unit reference signals seriousness. Yet suing an independent researcher over vulnerability publication carries risks. Courts have viewed public interest disclosures favorably in some jurisdictions. Facts about account handling and prior communications would likely surface. Microsoft has not commented on specific allegations of account deletion or unpaid reports.

The feud shows no signs of cooling. The researcher maintains control over additional material and vows escalation. Microsoft continues to push coordinated disclosure while racing to patch what lands in the wild. Security teams worldwide monitor for new drops and update defenses accordingly. July 14 now carries unusual weight on the calendar.

Whether the promised release materializes, and what it contains, will test both sides further. For now the public receives a rare view inside the strained relationship between one of technology’s largest vendors and the independent experts who find its flaws. Trust, once damaged, proves hard to restore. Customers pay the price in the meantime.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us