{"id":27636,"date":"2026-05-29T10:16:31","date_gmt":"2026-05-29T01:16:31","guid":{"rendered":"https:\/\/aireviewirush.com\/?p=27636"},"modified":"2026-05-29T10:16:31","modified_gmt":"2026-05-29T01:16:31","slug":"microsoft-threatens-researcher-over-bug-reviews-triggers-cybersecurity-uproar","status":"publish","type":"post","link":"https:\/\/aireviewirush.com\/?p=27636","title":{"rendered":"Microsoft Threatens Researcher Over Bug Reviews, Triggers Cybersecurity Uproar"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"article\">\n<p>The cybersecurity neighborhood is blasting Microsoft for threatening authorized motion in opposition to a disgruntled researcher who\u2019s been exposing Home windows vulnerabilities outdoors the corporate\u2019s regular disclosure course of.\u00a0<\/p>\n<p>The controversy offers with a researcher generally known as \u201cNightmare Eclipse,\u201d who has revealed <a href=\"https:\/\/blog.barracuda.com\/2026\/05\/19\/nightmare-eclipse-zero-days-grudge\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"noopener\">six<\/a> unpatched \u201czero-day\u201d flaws in latest weeks. This features a proof-of-concept exploit for a Home windows vulnerability generally known as BlueHammer that may enable an attacker to escalate their privileges to the administrator degree.\u00a0<\/p>\n<p>Researchers usually submit such findings to the Microsoft Safety Response Heart (MSRC) for patching to forestall hackers from exploiting them. However Nightmare Eclipse has intentionally ignored the accountable disclosure route, citing claims that Microsoft mistreated them.\u00a0<\/p>\n<p>\u201cThey mopped the ground with me and pulled each infantile sport they might,\u201d the researcher <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/04\/public-disclosure-response-for-cve-2026.html\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"noopener\">wrote<\/a> final month, with out elaborating. \u201cIt was soo unhealthy sooner or later I used to be questioning if I used to be coping with an enormous company or somebody who&#8217;s simply having enjoyable seeing me undergo however it appears to be a collective choice.\u201d<\/p>\n<p>The stress solely escalated after Nightmare Eclipse disclosed extra flaws this month, <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/05\/two-more-public-disclosures-it-will.html\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"noopener\">writing<\/a>: \u201cMicrosoft has chosen to make this worst as an alternative of resolving the scenario like adults, they pulled each infantile sport potential.\u201d <\/p>\n<p>On Wednesday, the software program big responded with its personal weblog put up that reiterated the necessity for accountable disclosure to forestall hackers from abusing such flaws and contained a authorized risk.\u00a0\u00a0<\/p>\n<p>\u201cUncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the palms of unhealthy actors are by no means justifiable and have real-world penalties,\u201d the corporate <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/blog\/2026\/05\/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure?source=post_page-----0946117940a4---------------------------------------\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"noopener\">wrote<\/a>, later including: \u201cOur Digital Crimes Unit will proceed bringing circumstances in opposition to these actors <strong><em>and people who allow their legal exercise<\/em><\/strong> \u2013 coordinating as wanted with regulation enforcement world wide.\u201d\u00a0<\/p>\n<p>Microsoft goes on to say \u201cany disclosure outdoors correct coordination\u201d might hurt its clients. However that final half about pursuing potential prices in opposition to Nightmare Eclipse has sparked an uproar within the cybersecurity neighborhood since one might argue the researcher is doing Microsoft a service by exposing vital bugs.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\"><p>\n    <a class=\"text-gray-600\" href=\"https:\/\/twitter.com\/vxunderground\/status\/2060036224245432506\" title=\"(Opens in a new tab)\" target=\"_blank\" rel=\"noopener\"><br \/>\n        This Tweet is at the moment unavailable. It may be loading or has been eliminated.<br \/>\n    <\/a>\n<\/p><\/blockquote>\n<p>\u201cMicrosoft will do something to cease folks posting zero-days besides repair MSRC,\u201d <a href=\"https:\/\/x.com\/ZackKorman\/status\/2059953731769131291\" target=\"_blank\" title=\"(Opens in a new tab)\">tweeted<\/a> Zack Korman, CTO of cybersecurity supplier Pistachio. Different researchers are <a href=\"https:\/\/x.com\/podalirius_\/status\/2059892083029069929\" target=\"_blank\" title=\"(Opens in a new tab)\">sharing<\/a> their <a href=\"https:\/\/x.com\/rootsecdev\/status\/2059812934511940091\" target=\"_blank\" title=\"(Opens in a new tab)\">tales<\/a> of <a href=\"https:\/\/x.com\/GabrielLandau\/status\/2059990548337828090\" target=\"_blank\" title=\"(Opens in a new tab)\">reporting<\/a> a flaw to Microsoft, however the firm refusing to pay a reward or formally fixing the issue and quietly issuing a patch later.<\/p>\n<p>&#8220;MSRC strung me alongside for a couple of further months\u00a0to maintain me quiet, then broke their phrase&#8230;.The interplay left such a foul style in my mouth that I don\u2019t actually really feel like interacting with\u00a0them once more,&#8221; wrote Gabriel Landau, a cybersecurity researcher and developer of anti-malware packages for Home windows. <\/p>\n<p>Nvidia help engineer Eric Warnke additionally <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7465721672780632064\/\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"noopener\">wrote<\/a> of Microsoft: \u201cYou can not compel unbiased safety researchers. You&#8217;ll be able to solely make it kind of engaging to work with you. Microsoft made it much less engaging, and now they&#8217;re writing weblog posts about shared accountability. That is a CYA, not a bug program designed to encourage reporting.\u201d\u00a0<\/p>\n<div class=\"py-4\" data-parent-group=\"related-stories\">\n<div class=\"mx-0 border border-b border-l-0 border-r-0 border-t border-gray-300 py-4 md:ml-8 md:mr-24\">\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_53 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title \" >Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\" role=\"button\"><label for=\"item-6a20a5985c1f4\" ><span class=\"\"><span style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input aria-label=\"Toggle\" aria-label=\"item-6a20a5985c1f4\"  type=\"checkbox\" id=\"item-6a20a5985c1f4\"><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><ul class='ez-toc-list-level-3'><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/aireviewirush.com\/?p=27636\/#Really_helpful_by_Our_Editors\" title=\"Really helpful by Our Editors\">Really helpful by Our Editors<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/aireviewirush.com\/?p=27636\/#About_Our_Skilled\" title=\"About Our Skilled\">About Our Skilled<\/a><\/li><\/ul><\/nav><\/div>\n<h3 class=\"font-stretch-ultra-condensed mb-2 text-lg font-semibold uppercase\"><span class=\"ez-toc-section\" id=\"Really_helpful_by_Our_Editors\"><\/span>Really helpful by Our Editors<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<\/p><\/div>\n<\/div>\n<blockquote class=\"twitter-tweet\"><p>\n    <a class=\"text-gray-600\" href=\"https:\/\/twitter.com\/curi0usJack\/status\/2059744774039474215\" title=\"(Opens in a new tab)\" target=\"_blank\" rel=\"noopener\"><br \/>\n        This Tweet is at the moment unavailable. It may be loading or has been eliminated.<br \/>\n    <\/a>\n<\/p><\/blockquote>\n<p>Kevin Beaumont, a safety researcher who beforehand labored at Microsoft, can also be uncertain that Remond might efficiently sue anybody for violating an organization&#8217;s accountable disclosure coverage, which is commonly set by the corporate itself.\u00a0\u00a0\u00a0<\/p>\n<p>\u201cIf Microsoft\u2019s tactic is to attempt to criminalize not following typically arbitrary \u2018accountable disclosure\u2019 frameworks, good luck defending that in courtroom \u2014 as a result of there\u2019s an entire clown automobile of prior choice making inside Microsoft and details which might emerge in that course of,\u201d he <a href=\"https:\/\/doublepulsar.com\/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4?postPublishedType=repub\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"noopener\">wrote<\/a> noting that the Microsoft-owned Github typically hosts software program exploits and hacking methods, however does not essentially take away them. \u00a0<\/p>\n<p>\u201cMicrosoft must be concentrating on making higher, safer merchandise that one particular person can\u2019t run rings round,\u201d he added.\u00a0<\/p>\n<p>Within the meantime, each the GitHub and GitLab pages for Nightmare Eclipse have been taken down, together with their MSRC account, stopping them from correctly disclosing future bugs to Microsoft. Nonetheless, the researcher has <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/05\/july-14th.html\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"noopener\">threatened<\/a> to publish a\u00a0 new vulnerability on July 14, warning: \u201cI&#8217;ll be sure that your bones are shattered that day.\u201d<\/p>\n<section class=\"rich-text my-16 flex flex-col gap-6\" data-parent-group=\"author-bio\" aria-label=\"About Our Expert\">\n<h2 class=\"!m-0\"><span class=\"ez-toc-section\" id=\"About_Our_Skilled\"><\/span>About Our Skilled<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<div class=\"flex flex-col gap-8\">\n<div class=\"flex flex-col gap-6 rounded-lg bg-white p-6 text-gray-700 shadow-box md:p-10\" id=\"flyout\" role=\"tooltip\" aria-label=\"Author Bio Flyout\">\n<div class=\"font-stretch-ultra-condensed flex items-center justify-between leading-tight\">\n<div class=\"flex gap-4\">\n                                                            <img decoding=\"async\" class=\"size-[60px] shrink-0 overflow-hidden rounded-full bg-gray-100 ring ring-white\" src=\"https:\/\/i.pcmag.com\/imagery\/authors\/06W4G6A5rmg4LxEffqKnnc6.fit_lim.size_100x100.v1560221550.png\" alt=\"Michael Kan\"\/><\/p>\n<div class=\"flex flex-col justify-center gap-1\">\n<p>Michael Kan<\/p>\n<p>Principal Reporter<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"!m-0 border-t border-gray-300\"\/>\n<div class=\"flex flex-col gap-2\">\n<p>Expertise<\/p>\n<div class=\"rich-text line-clamp-[7] text-base leading-normal\">\n<p>I have been a journalist for over 15 years. I acquired my begin as a colleges and cities reporter in Kansas Metropolis and joined PCMag in 2017, the place I cowl satellite tv for pc web companies, cybersecurity, PC {hardware}, and extra. I am at the moment based mostly in San Francisco, however beforehand spent over 5 years in China, protecting the nation&#8217;s expertise sector.<\/p>\n<p>Since 2020, I&#8217;ve coated the launch and explosive progress of SpaceX&#8217;s Starlink satellite tv for pc web service, writing 600+ tales on availability and have launches, but in addition the regulatory battles over the enlargement of satellite tv for pc constellations, fights with rival suppliers like AST SpaceMobile and Amazon, and the trouble to increase into satellite-based cell service. I&#8217;ve combed via FCC filings for the most recent information and pushed to distant corners of California to check Starlink&#8217;s mobile service. <\/p>\n<p>I additionally cowl cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, <a href=\"https:\/\/www.pcmag.com\/news\/did-avast-sell-your-data-heres-how-to-get-a-piece-of-the-ftc-settlement\" target=\"_self\" rel=\"noopener\">the FTC pressured Avast<\/a> to pay customers $16.5 million for secretly harvesting and promoting their private info to third-party purchasers, as revealed in my joint <a href=\"https:\/\/www.pcmag.com\/news\/the-cost-of-avasts-free-antivirus-companies-can-spy-on-your-clicks\" target=\"_self\" rel=\"noopener\"><u>investigation<\/u><\/a> with Motherboard.<\/p>\n<p>I additionally cowl the PC graphics card market. Pandemic-era shortages <a href=\"https:\/\/www.pcmag.com\/news\/i-camped-out-at-best-buy-to-get-an-rtx-3000-graphics-card-feel-my-pain\" target=\"_self\" rel=\"noopener\">led me to camp out<\/a> in entrance of a Finest Purchase to get an RTX 3000. I am now following how the AI-driven reminiscence scarcity is impacting your entire shopper electronics market. I am all the time desperate to study extra, so please soar within the feedback with suggestions and ship me suggestions.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p>                                        <a class=\"w-fit self-end text-base font-bold uppercase leading-none underline\" data-module=\"author-bio\" data-element=\"read-full-bio\" data-item=\"text_link\" data-position=\"1\" href=\"https:\/\/www.pcmag.com\/authors\/michael-kan\" aria-label=\"Michael Kan &#039;s Full Author Bio\" x-track-ga-click=\"\" target=\"_blank\" rel=\"noopener\"><br \/>\n                        Learn Full Bio<br \/>\n                    <\/a>\n                <\/div>\n<\/p><\/div>\n<\/section><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script>\n    var facebookPixelLoaded = false;\n    window.addEventListener('load', function() {\n        document.addEventListener('scroll', facebookPixelScript);\n        document.addEventListener('mousemove', facebookPixelScript);\n    });\n    function facebookPixelScript() {\n        if (!facebookPixelLoaded) {\n            facebookPixelLoaded = true;\n            document.removeEventListener('scroll', facebookPixelScript);\n            document.removeEventListener('mousemove', facebookPixelScript);\n            window.zdconsent.cmd.push(function() {\n                ! function(f, b, e, v, n, t, s) {\n                    if (f.fbq) return;\n                    n = f.fbq = function() {\n                        n.callMethod ? n.callMethod.apply(n, arguments) : n.queue.push(arguments)\n                    };\n                    if (!f._fbq) f._fbq = n;\n                    n.push = n;\n                    n.loaded = !0;\n                    n.version = '2.0';\n                    n.queue = [];\n                    t = b.createElement(e);\n                    t.async = !0;\n                    t.src = v;\n                    s = b.getElementsByTagName(e)[0];\n                    s.parentNode.insertBefore(t, s)\n                }(window, document, 'script', '\/\/connect.facebook.net\/en_US\/fbevents.js');\n                fbq('init', '454758778052139');\n                fbq('track', \"PageView\");\n            });\n        }\n    }\n<\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cybersecurity neighborhood is blasting Microsoft for threatening authorized motion in opposition to a disgruntled researcher who\u2019s been exposing Home windows vulnerabilities outdoors the corporate\u2019s regular disclosure course of.\u00a0 The controversy offers with a researcher generally known as \u201cNightmare Eclipse,\u201d who has revealed six unpatched \u201czero-day\u201d flaws in latest weeks. This features a proof-of-concept exploit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":27638,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-27636","post","type-post","status-publish","format-standard","has-post-thumbnail","category-input-devices"],"_links":{"self":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/27636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=27636"}],"version-history":[{"count":1,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/27636\/revisions"}],"predecessor-version":[{"id":27637,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/27636\/revisions\/27637"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/media\/27638"}],"wp:attachment":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=27636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=27636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=27636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}