Microsoft’s GitHub bans security researcher who posted Windows zero-day exploits after claims of retaliation and controversy

Microsoft bans GitHub account of security researcher amid dispute over Windows zero-day disclosures

Microsoft bans GitHub account of security researcher amid dispute over Windows zero-day disclosures

Microsoft has reportedly banned the GitHub account of a security researcher known as Nightmare-Eclipse (also referred to as Chaotic Eclipse), escalating an ongoing dispute in the Windows security community. The researcher claims to have discovered and published multiple Windows zero-day vulnerabilities, some of which allegedly affect core components such as Microsoft Defender, system services, and BitLocker. According to the report, Microsoft also removed the Microsoft account used by the researcher for submitting vulnerability reports, though the company has not publicly detailed the reasons behind these actions.

The researcher argues that Microsoft’s response is retaliatory and stems from unresolved disputes over vulnerability disclosures and bug bounty payments. Microsoft’s Security Response Center (MSRC) program typically pays significant rewards for valid security findings, but the researcher claims they received no compensation despite submitting multiple reports. In response to the ban, they have reportedly moved their work to GitLab and continued posting exploits.

The situation has attracted attention from security experts, some of whom suggest that Microsoft’s internal vulnerability handling processes may have become less effective or overly bureaucratic. Others highlight that publishing working exploit code publicly can increase security risks, especially if vulnerabilities are already being actively exploited in the wild.

The controversy has intensified due to statements attributed to the researcher indicating further planned disclosures and retaliation dates tied to upcoming Microsoft patch cycles. Microsoft has not issued a detailed public statement on the case, leaving uncertainty about whether the ban was due to policy violations, unsafe disclosure practices, or other conduct concerns. The incident has sparked broader debate about responsible disclosure, platform governance, and how major tech companies should handle independent security researchers.

Leave a Reply

Your email address will not be published. Required fields are marked *