Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Addresses Concerns Over Zero-Day Vulnerability Disclosures

Microsoft Addresses Concerns Over Zero-Day Vulnerability Disclosures

Posted on June 3, 2026 By CWS

Microsoft has recently addressed the concerns arising from its initial response to the public disclosure of zero-day vulnerabilities by researchers without prior notification. This move came after a backlash that involved legal threat fears from the cybersecurity community.

Researcher Discloses Multiple Vulnerabilities

The situation centers around a researcher known as Chaotic Eclipse and Nightmare Eclipse, who revealed proof-of-concept (PoC) exploits for several undisclosed vulnerabilities affecting Microsoft products. These disclosures were made following disagreements during the vulnerability reporting process with Microsoft.

Among the vulnerabilities disclosed are RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), BlueHammer (CVE-2026-33825), YellowKey (CVE-2026-45585), GreenPlasma, and MiniPlasma. Notably, YellowKey allows BitLocker protection to be bypassed, while UnDefend involves a denial-of-service vulnerability in Microsoft Defender.

Microsoft’s Response and Community Reaction

As the vulnerabilities started being exploited in real-world scenarios, Microsoft began deploying patches and mitigation strategies. However, the situation escalated when the researcher accused Microsoft of ignoring communications, failing to provide compensation, and publicly defaming them, leading to the company’s decision to disable the researcher’s accounts on its platforms.

Microsoft defended its actions, emphasizing that uncoordinated disclosures of PoC code for unpatched vulnerabilities expose users to unnecessary risks. The company highlighted the role of its security teams in addressing such threats and its intention to collaborate with law enforcement when laws are broken.

Clarifications and Future Outlook

Following the public backlash, Microsoft issued clarifications via social media, reaffirming its appreciation for the security research community. The tech giant stressed that it does not intend to pursue legal action against researchers conducting legitimate security research, but will take necessary actions against malicious activities.

The incident has sparked discussions within the cybersecurity community about the balance between responsible disclosure and the potential risks of releasing vulnerability details without prior coordination with vendors. Microsoft has expressed its commitment to fostering constructive relationships with researchers and ensuring respectful engagement moving forward.

As the situation develops, the researcher, Nightmare Eclipse, has indicated plans to release further exploits, including a full BitLocker bypass. This ongoing dialogue highlights the complexities involved in vulnerability disclosure and the critical role of collaboration in maintaining cybersecurity.

Security Week News Tags:BitLocker, cyber threats, Cybersecurity, Defender, Exploits, legal action, Microsoft, Patches, security research, Software Security, tech news, Vulnerability, vulnerability disclosure, zero-day

Post navigation

Previous Post: New HTTP/2 Bomb Exploit Threatens Major Web Servers
Next Post: Critical Flaw in Microsoft 365 Android Apps Risked User Accounts

Related Posts

Oracle Patches EBS Vulnerability Allowing Access to Sensitive Data Oracle Patches EBS Vulnerability Allowing Access to Sensitive Data Security Week News
Vercel Confirms Intrusion After Hacker’s Data Sale Offer Vercel Confirms Intrusion After Hacker’s Data Sale Offer Security Week News
In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment In Other News: Nvidia Says No to Backdoors, Satellite Hacking, Energy Sector Assessment Security Week News
Microsoft’s Project Ire Autonomously Reverse Engineers Software to Find Malware Microsoft’s Project Ire Autonomously Reverse Engineers Software to Find Malware Security Week News
DarkSword iOS Exploit Kit Targets Global iPhones DarkSword iOS Exploit Kit Targets Global iPhones Security Week News
US Cybersecurity Worker Admits Role in Ransomware Scams US Cybersecurity Worker Admits Role in Ransomware Scams Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark