惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

The Stack

How Lloyds has transformed its trusted critical data for AI Micron's revenue surges with no end to the memory shortage in sight Ubiquiti UniFi OS vulnerabilities exploited in the wild Mistral's new OCR 4 model shows size matters EU approves €76m in state aid for chip testing firm Even FedEx is a winner of the data centre boom Why AWS thinks AI coding assistants need a new place to run Why China is forging closer ties with open-source foundations China's CPU-only supercomputer tops power list Runtime: Why 'Bring-your-own-Cloud' is taking off; the TRAIT&R framework for agents, and... AWS adds yet another security tool to speed up patching Scattered Spider: UK teen pleads guilty to TfL attack OSS security finally gets a Magic Quadrant Places for People forking out £60m for new ERP system Google offers ATT&CK for bad AI, with surging cost forecast STACKUP: The Stack's weekly tech startups and funding wrap Bring Your Own Cloud: why more enterprises are buying in AWS takes NVIDIA "G7" Blackwell instances GA Runtime: Vercel sets up a new framework for agents, Databricks finds a new Genie, and… Borussia Dortmund's IT head has to sometimes think "outside of the box" Accenture stumbles after Middle East, AI, merger questions Cabinet Office offering £100k+ for AI "ambassador" Critical Splunk Enterprise vulnerability being exploited Accenture buys majority stake in OT security company Dragos npm's security rethink, Satya’s warning, a COBOL win, and... US spending billions to counter China's tech influence NatGeo Society CTO on migrating 15 years of video data to the cloud Alibaba opens French data centres in Europe cloud push SpaceX to take over Cursor in $60bn play for AI coding market Hosting firm Hetzner hikes prices sharply amid supply chain pain
Microsoft turns down temperature amid Nightmare Eclypse row
The Stack · 2026-06-01 · via The Stack

Microsoft Security Response Center (MSRC) on May 27 appeared to threaten legal action over the uncoordinated disclosure of six impactful zero days.

Now it’s trying to turn down the temperature. 

The central security team has faced a public barrage of criticism from a security researcher going by the handle Nightmare Eclipse/Chaotic Eclipse.

The researcher, believed to be young, alleges that MSRC has attempted to muzzle them – ultimately shutting down their GitHub and GitLab accounts after they publicly posted a flurry of exploits for bugs they had found.

In a May 27 blog, MSCR had pointed specifically to the ongoing situation and then commented that “Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these…Our Digital Crimes Unit will continue bringing cases against these actors.”

“Literally gave me free vulnerabilities”

Many in the security community took that as a highly regressive threat to penalise public bug disclosure outside of MSRCs “coordinated vulnerability disclosure” (CVD) programme.

In a show of solidarity, some even gifted potentially valuable (under bug bounty programmes) bugs to the researcher.

(As Nightmare Eclypse wrote on May 29: “Soooo, something extremely funny is happening. After the recent events, multiple researchers reached out to me and some just literally gave me free vulnerabilities…”) 

MSRC now says it is “listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile.”

"No intention to pursue action..."

In a post on social media today, Redmond’s team added: “We deeply value the security community, and will continue to take your feedback seriously. To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. 

“When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate. We recognize the work that goes into researching and submitting a vulnerability. We are committed to approaching every interaction with transparency, clear communication, and professionalism.”

“We acknowledge that some interactions have fallen short and are working to learn from them… We are committed to maintaining a constructive and respectful relationship and growing together. We know that, given the nature of this work, there will at times be misunderstandings. We remain committed to engaging in good faith and to providing a respectful and professional experience for all researchers, regardless of past interactions.”

The precise nature of Nightmare Eclypse’s relationship with Microsoft and their identity remain closely guarded. They have disclosed a series of highly novel vulnerabilities including a complete bypass of BitLocker encryption. 

The vulnerability, tracked as CVE-2026-45585 effectively makes any lost or stolen laptop a data breach incident and, as Microsoft admits, means a “successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data.” 

Other exploits published by the researcher let attackers abuse a trio of Microsoft Defender vulnerabilities, tracked as RedSun (CVE-2026-41091) , UnDefend (CVE-2026-45498) and BlueHammer (CVE-2026-33825) for privilege escalation and have since have been exploited in the wild.