Lounge Started May 29, 2026 7:26 PM

Microsoft escalates dispute with 0-day finder Nightmare Eclipse, leading to a revolt from cybersecurity community

3 replies - 87 views - 2 thanks - 1 tippers - 3 watchers

May 29, 2026 7:26 PM
#1

Article: https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085

Last week I made a thread about the Yellow Key exploit, which you can read here. The tl;dr is that a disgrunted 0-day hunter who goes by the name Nightmare Eclipse was tired of being ignored by Microsoft's disclosure team, so he uploaded an extremely critical exploit for everyone on github (in fact, this is one of four exploits, however the most severe). Yellow Key is a literal backdoor which breaks bitlocker encryption for any Windows 11 computer if you are able to locally access it (I tried it out by the way, and yes, it works).

This week, Microsoft responded and denied all accusations, threatened legal action, and referred to these events as "uncoordinated disclosures". They then suspended his account on github.

This week, in a signed message on his blog, Nightmare Eclipse responded with a pgp signed message. In addition to disputing Microsoft on everything, they claim that on July 14th a new exploit will be released that will be a big one. They also created a GitLab account.

Shortly thereafter, the GitLab was taken down. Presumably, due to some sort of cease and desist from Microsoft lawyers.

In response, security researchers began piling on Microsoft sharing their stories about the incompetence of the security team. You can see a collage of the tweets here.

Whether this continues to snowball remains to be seen, but Microsoft is showing how little they care about severe vulnerabilities, all but confirming they intentionally left a backdoor in for law enforcement (which would make sense...why would an encrypted application even have such a methodology of breaking in?).

2 thanks - 1 tippers - 3 watchers

Replies

Page 1 of 1 - 3 total
May 29, 2026 10:16 PM
#2

I always feel like people rely too much on these big platforms like github. hopefully he can get the stuff onto another platform or on his own, or get it shared some peer to peer way so it can't be taken down

Signature

I'm an artist (skills in vtuber making and livestreaming), wannabe singer, and chronically lonely loser- always willing to chat about nearly anything. Don't hesitate to start a convo with me.

0 thanks - 0 tippers
May 30, 2026 7:11 AM
#3

All the best to the bounty hunter. Fuck Microsoft.

0 thanks - 0 tippers

Post A Reply

You must be logged in to reply. Login or register.