Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Ars Technica News

Summary

Microsoft fixed a 0-day vulnerability disclosed by researcher Nightmare Eclipse amid a heated rivalry, alongside other vulnerabilities like MiniPlasma, YellowKey, and others. The researcher published exploit code for a new Windows Defender vulnerability.

<p>Microsoft on Tuesday released fixes for two high-severity zero-days that were disclosed by a researcher who has been locked in a testy beef with the software giant.</p> <p>Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-days that had the potential to be exploited in the wild. The researcher has said the disclosures, which included proof-of-concept code, came after Microsoft reneged on an arrangement the two made regarding vulnerabilities they had discussed.</p> <h2>Disclosure drama</h2> <p>“But someone violated our agreement and left me homeless with nothing,” Nightmare Eclipse <a href="https://deadeclipse666.blogspot.com/2026/03/">wrote</a> in March. “They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”</p><p><a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/">Read full article</a></p> <p><a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/#comments">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 06/10/26, 12:18 AM

# Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed Source: [https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/](https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/) Tuesday’s patch bundle also fixed[MiniPlasma](https://web.archive.org/web/20260521144855/https://github.com/Nightmare-Eclipse/MiniPlasma), a separate vulnerability disclosed by Nightmare Eclipse\. Microsoft said in an email that the vulnerability is tracked as CVE\-2020\-17103, a vulnerability Microsoft first fixed six years ago\. That means MiniPlasma was the result of a regression or an incomplete patch in its initial form\. The company is in the process of updating Tuesday’s bulletin to note the republication\. Microsoft has yet to release patches for other vulnerabilities disclosed by Nightmare Eclipse\. The company did[provide manual instructions](https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/)for mitigating YellowKey, a vulnerability that allows attackers to defeat Bitlocker full\-disk encryption\. That could be a boon when attackers have physical access to a device \(the precise scenario Bitlocker is designed to protect against\)\. The company has yet to fix the underlying cause of the vulnerability\. The status of other vulnerabilities disclosed by Nightmare Eclipse are also unclear at the moment\. The researcher named one vulnerability, present in Windows Defender[RedSun](lhttps://web.archive.org/web/20260520184528/https://github.com/Nightmare-Eclipse/RedSun)\. Another, named BlueHammer, is also a local privilege escalation flaw that provides SYSTEM rights\. Over the past few months, Nightmare Eclipse has taken multiple potshots at Microsoft\. The specific criticisms remain unclear, but many make references to complaints about the company’s vulnerability disclosure program\. Microsoft, in turn, has[publicly railed](https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure)against the researcher for “not responsibly” disclosing the vulnerabilities and made a vailed reference to the possibility of pursuing legal action\. After a public backlash, Microsoft later relented and vowed no such legal action would occur\. On Tuesday, Nightmare Eclipse[published](https://deadeclipse666.blogspot.com/)exploit code for a new Windows vulnerability\. It’s a race condition that targets Defender\. Tuesday’s patch batch included fixes for roughly 200 vulnerabilities\. Notwithstanding the appearance that MiniPlasma was fixed, two of them were also confirmed as zero\-days\. *Post updated to include information Microsoft provided after initial publication of this post\.*

Similar Articles

Mystery Microsoft bug leaker keeps the zero-days coming

Hacker News Top

An anonymous researcher released two Microsoft zero-day exploits, YellowKey (BitLocker bypass) and GreenPlasma (privilege escalation), after Patch Tuesday, posing serious security risks for organizations.