Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws

Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws

Posted on May 28, 2026 By CWS

Microsoft has voiced strong support for Coordinated Vulnerability Disclosure (CVD), encouraging researchers to share their discoveries with affected vendors in advance. This approach allows companies to assess and address issues before the vulnerabilities become public knowledge.

Public Disclosure of Zero-Day Vulnerabilities

The statement from Microsoft follows the actions of a researcher known as Chaotic Eclipse, who revealed several zero-day vulnerabilities in various Windows components, including Defender and BitLocker. The researcher criticized Microsoft’s handling of the disclosure process, leading to the public release of these vulnerabilities.

Microsoft expressed concern over these disclosures, stating, “In recent weeks, several zero-day vulnerabilities have been publicly disclosed without prior communication with Microsoft. This exposure puts our customers at unnecessary risk.”

Active Exploitation and Response

The vulnerabilities identified include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma, and MiniPlasma. Among these, BlueHammer, RedSun, and UnDefend are reportedly being actively exploited.

Microsoft’s security teams are working tirelessly to understand the implications of these vulnerabilities, protect users, and develop necessary security updates. The company strongly opposes the release of proof-of-concept code for unpatched vulnerabilities, emphasizing the potential real-world consequences when such information is misused.

Calls for Dialogue and Cooperation

Microsoft emphasized the importance of diverse perspectives in enhancing security, stating, “We welcome different viewpoints that foster collaboration within the security community to protect everyone.” The company reiterated its commitment to transparency and dialogue through various avenues, including researcher appreciation events and security conferences.

As a result of the disclosures, GitHub has removed Chaotic Eclipse’s account, and although the exploit code was reposted on GitLab, this account has also been restricted.

Researcher’s Response and Future Actions

The researcher, in a public post, criticized Microsoft’s response to their communication efforts, alleging defamation and unfair treatment. They highlighted an advisory related to CVE-2026-45585 and claimed that their account was unjustly deleted.

The researcher announced plans to release further information on July 14, 2026, hinting at significant future developments. This ongoing situation underscores the tension between independent researchers and major tech companies in handling vulnerability disclosures.

The Hacker News Tags:BitLocker, Chaotic Eclipse, CVD, Cybersecurity, Disclosure, GitHub, Microsoft, Security, Vulnerability, Windows, zero-day

Post navigation

Previous Post: Critical Gitea Vulnerability Risks Private Container Images
Next Post: Carnival Breach: 6 Million Affected by Data Theft

Related Posts

UNC6426 Leverages npm Flaw for Rapid AWS Admin Access UNC6426 Leverages npm Flaw for Rapid AWS Admin Access The Hacker News
Entra ID Data Protection: Essential or Overkill? Entra ID Data Protection: Essential or Overkill? The Hacker News
Warlock Ransomware Exploits Unpatched SmarterMail Server Warlock Ransomware Exploits Unpatched SmarterMail Server The Hacker News
Zero Trust Data Movement: The Overlooked Challenge Zero Trust Data Movement: The Overlooked Challenge The Hacker News
Spear-Phishing Campaign Targets Uzbekistan and Russia Spear-Phishing Campaign Targets Uzbekistan and Russia The Hacker News
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Carnival Breach: 6 Million Affected by Data Theft
  • Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws
  • Critical Gitea Vulnerability Risks Private Container Images
  • BTMOB Android Malware Threatens Full Device Control
  • Hackers Exploit Networks for JavaScript Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Carnival Breach: 6 Million Affected by Data Theft
  • Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws
  • Critical Gitea Vulnerability Risks Private Container Images
  • BTMOB Android Malware Threatens Full Device Control
  • Hackers Exploit Networks for JavaScript Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark