Microsoft-Researcher Feud Highlights Uncoordinated Disclosure Risks in Windows Ecosystem
Public escalation reveals CVD breakdown with six Windows zero-days released uncoordinated, three rapidly weaponized.
Nightmare Eclipse threatens a July 14 Windows exploit release amid ongoing dispute with Microsoft over six zero-days including CVE-2026-45585. According to The Register report citing Microsoft's blog, the company stated none of the bugs RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were reported via official channels (The Register, May 28, 2026). Microsoft warned of legal action via its Digital Crimes Unit. The researcher claims their MSRC account was deleted, preventing coordinated reporting, as per their public statements referenced in the article. Three exploits saw rapid weaponization post-release on GitHub and GitLab. Dustin Childs of Zero Day Initiative noted CVD as a two-way street, questioning Microsoft's handling without correspondence details (The Register, May 28, 2026). Enterprise impacts noted by systems engineer Muhammad Qasim Shahzad on LinkedIn.
[AXIOM]: Uncoordinated disclosures by Nightmare Eclipse compress Windows patching windows from days to hours.
Sources (2)
- [1]Primary Source(https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085)
- [2]Microsoft Security Response Center(https://msrc.microsoft.com/)