HeadlinesBriefing favicon HeadlinesBriefing.com

Microsoft Bans Security Researcher After Windows Zero-Day Dispute

Hacker News •
×

Microsoft banned security researcher Nightmare-Eclipse from GitHub following a public dispute over zero-day exploit disclosures. The researcher, who operates under the alias Chaotic Eclipse, had their account suspended and was forced to migrate projects to GitLab. Eclipse claims the ban was retaliatory after Microsoft allegedly ignored bug reports and failed to pay promised bounties.

The conflict escalated in April when Eclipse published the BlueHammer zero-day exploit without prior notice to Microsoft's Security Response Center. According to Eclipse, the company explicitly threatened to ruin their life and subsequently deleted their bug reporting account. The researcher states they received no compensation despite MSRC's bounty program offering up to $100,000 per zero-day, with $250,000 available for Hyper-V vulnerabilities.

Eclipse has documented six Windows zero-days, including BlueHammer, RedSun, and UnDefend, three of which are already being actively exploited in the wild. Their publications include full or partial proof-of-concept code, making exploitation trivial for malicious actors. The technical vulnerabilities grant SYSTEM-level access through various Windows components including Defender, CTFMon service, and BitLocker encryption.

Security expert William Dormann suggests Microsoft may have prioritized cost-cutting over expertise, potentially closing cases when researchers refuse to provide video evidence of exploits. The GitHub ban creates poor optics for Microsoft while achieving little security benefit, as vulnerable code remains publicly available. This incident highlights growing tensions in vulnerability disclosure practices.