Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
https://thehackernews.com/2026/05/microsoft-slams-public-zero-day.html
Publish Date: 2026-05-28 09:53:00
Source Domain: thehackernews.com
Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed.
The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day vulnerabilities affecting various Windows components, including Defender and BitLocker, over the past month, citing a breakdown in Microsoft’s handling of the vulnerability disclosure process.
“In recent weeks, several zero-day vulnerabilities have been publicly disclosed,” the tech giant said. “The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk.”
“In response to the unnecessary risk created by these disclosures, our security teams have been working around the clock to understand the impact, protect our customers, and develop security updates.”
The vulnerabilities include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma, and MiniPlasma. Following disclosure, BlueHammer, RedSun, and UnDefend have all come under active exploitation in the wild.
Microsoft said it “firmly” opposes such uncoordinated disclosures and that putting proof-of-concept code for unpatched vulnerabilities can have “real-world consequences” when they end up in the hands of bad actors.
“We invite diverse perspectives that help the security community work together to protect everyone. We realize that we will not always agree on everything, but we are committed to transparency and continue to create opportunities for dialogue,” the tech giant added.
“These conversations happen at researcher appreciation events, security conferences, and the everyday work we do together…