{"id":54234,"date":"2026-05-29T13:47:56","date_gmt":"2026-05-29T17:47:56","guid":{"rendered":"https:\/\/overcentral.com\/en\/researcher-unleashes-6-windows-zero-days-msrc-trust-collapses\/"},"modified":"2026-05-29T13:49:17","modified_gmt":"2026-05-29T17:49:17","slug":"windows-zero-days-trust-collapse","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/windows-zero-days-trust-collapse\/","title":{"rendered":"Researcher Unleashes 6 Windows Zero-Days, MSRC Trust Collapses"},"content":{"rendered":"<p>The discovery and coordinated disclosure of software vulnerabilities has long relied on a fragile compact between independent researchers and the world\u2019s largest technology companies. In the spring of 2026, that compact has shattered in spectacular fashion. An anonymous security researcher operating under the pseudonym Nightmare Eclipse, also known as Chaotic Eclipse, has publicly released proof-of-concept exploit code for six distinct Windows <a href=\"https:\/\/overcentral.com\/en\/anthropic-project-glasswing-zero-day-vulnerabilities\/\" title=\"Anthropic Project Glasswing Unearths Over 10,000 Zero-Day Vulnerabilities\" data-iacss-internal=\"1\">zero-day vulnerabilities<\/a> over a span of just six weeks. The resulting crisis has not only put millions of systems at risk but has laid bare what many in the security community describe as a catastrophic collapse of trust between Microsoft and the very researchers its security programs were designed to attract.<\/p>\n<h2>The Six-Week Cascade: Six Zero-Days Released in Rapid Succession<\/h2>\n<p>The sequence of events began on April 2, 2026, when Nightmare Eclipse published the first exploit code on GitHub. This initial vulnerability, named <strong>BlueHammer<\/strong> (CVE-2026-33825), targeted a time-of-check\/time-of-use (TOCTOU) race condition within the Windows Defender threat remediation engine, allowing an attacker to achieve local privilege escalation (LPE) to SYSTEM level. Critically, this release bypassed any form of coordinated vulnerability disclosure (CVD). There was no prior notice to Microsoft, no 90-day window for patch development, and no private communication channel. The exploit was simply published for the world to see and use.<\/p>\n<p>Over the following five weeks, the researcher continued a relentless pace of public disclosures. On April 16, two additional flaws in Microsoft Defender were released simultaneously. <strong>RedSun<\/strong> (CVE-2026-41091) exploited a race condition in the Defender anti-malware engine to achieve LPE, while <strong>UnDefend<\/strong> (CVE-2026-45498) silently halted Defender\u2019s definition file updates while falsely reporting a healthy state to the management console. Microsoft responded to the first wave with an out-of-band patch on <a href=\"https:\/\/overcentral.com\/en\/starbites-switch-2-version-delayed-other-platforms-launch-may-21\/\" title=\"Starbites Switch 2 version delayed, other platforms launch May 21\" data-iacss-internal=\"1\">May 21<\/a>. A second wave followed in mid-May. <strong>YellowKey<\/strong> (CVE-2026-45585) provided a full bypass of BitLocker encryption on any drive accessible via a USB port and physical access. <strong>GreenPlasma<\/strong> was a privilege escalation in the Windows text input service component, and <strong>MiniPlasma<\/strong> achieved SYSTEM-level access through the Windows Cloud Filter driver. Security firm Huntress confirmed that by mid-April, BlueHammer, RedSun, and UnDefend were already being used in real-world attacks, with threat actors combining them for privilege escalation and Defender neutralization.<\/p>\n<h2>How Did Microsoft Respond, and Why Is the Response So Controversial?<\/h2>\n<p>Microsoft\u2019s official reaction came on <a href=\"https:\/\/overcentral.com\/en\/007-first-light-global-launch\/\" title=\"007 First Light Launches Globally on May 27\" data-iacss-internal=\"1\">May 27<\/a>, 2026, through a blog post from the <a href=\"https:\/\/msrc.microsoft.com\/blog\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Microsoft Security Response Center<\/a> (MSRC). The company stated unequivocally that none of the six vulnerabilities had been reported to Microsoft prior to their public release, emphasizing the importance of coordinated vulnerability disclosure. The post also contained a significant and deliberately vague statement, noting that the Microsoft Digital Crimes Unit (DCU) would \u201ccontinue to work with law enforcement agencies around the world to pursue criminals.\u201d This language was widely interpreted as a veiled threat of legal action against the researcher. Crucially, Microsoft did not answer the most pressing questions: whether the researcher was a current or former employee, whether their MSRC account had been deactivated, or whether the company intended to file a lawsuit.<\/p>\n<p>Nightmare Eclipse responded publicly on May 24, claiming precisely that\u2014their Microsoft account, used exclusively for reporting vulnerabilities to MSRC, had been deliberately deactivated without explanation. The researcher stated they had never received a bounty for any of their previous reports and had continued submitting findings on a pro bono basis solely to improve Windows security. The post ended with a stark promise: a further release of zero-day exploits was scheduled for July 14, the date of the next Patch Tuesday.<\/p>\n<h2>Industry Experts Condemn Microsoft\u2019s Handling of the Crisis<\/h2>\n<p>Microsoft\u2019s response has drawn sharp criticism from some of the most respected figures in vulnerability research. Katie Moussouris, the founder of Luta Security and a former Microsoft employee who created the company\u2019s original bug bounty program, characterized the company\u2019s blog post as \u201ca contradictory message.\u201d She pointed out a critical inconsistency: Microsoft claimed its program \u201cpays bounties and publicly credits researchers,\u201d yet the researcher in question maintained they had received neither compensation nor credit. Moussouris also highlighted a significant linguistic regression. Microsoft used the term \u201cresponsible disclosure\u201d in its blog post, a phrase she had helped retire from the company\u2019s lexicon over a decade ago in favor of \u201ccoordinated vulnerability disclosure,\u201d precisely because the older term carried a paternalistic and judgmental tone that punished researchers.<\/p>\n<p>Dustin Childs, a former Microsoft employee with roughly seven years of experience at the company and now the threat awareness lead at Trend Micro\u2019s Zero Day Initiative (ZDI), was equally blunt. \u201cCVD is a two-way street,\u201d Childs stated. \u201cThe vendor bears responsibility too.\u201d He criticized Microsoft for publicly denouncing the researcher for violating CVD while simultaneously refusing to reveal the specifics of their own interactions with the researcher, leaving the community to wonder whether the company had actually failed to respond to legitimate reports. Childs also noted a dangerous practical consequence: many researchers in the community are now actively avoiding working with Microsoft. \u201cWhen the severity is moderate rather than critical, the process becomes difficult,\u201d he explained. \u201cI\u2019ve heard researchers say they have completely stopped auditing Microsoft products.\u201d<\/p>\n<p>Kevin Beaumont, a former Microsoft employee and respected security researcher, described the situation as \u201ca massive bonfire of self-own\u201d by Microsoft. He pointed to the stark inconsistency in the company\u2019s historical behavior. When a researcher known as SandboxEscaper publicly released Windows zero-day PoC exploits in the past, Microsoft ultimately hired that individual. The same behavior that was once rewarded with employment is now being framed as criminal activity.<\/p>\n<p>Will Dormann, a vulnerability analyst at Tharros who independently validated the BlueHammer exploit in April, offered a particularly damning assessment of MSRC\u2019s internal health. \u201cMSRC used to be an absolutely stellar organization,\u201d Dormann stated. \u201cBut cost-cutting led to layoffs of experienced talent, and all that\u2019s left are people who just read flowcharts.\u201d<\/p>\n<h2>What Broke Was Trust, Not Just Vulnerabilities<\/h2>\n<p>Moussouris described the underlying dynamic as fundamentally asymmetric\u2014a \u201cDavid versus Goliath\u201d power structure. The security researcher possesses technical leverage, but the vendor possesses legal, financial, and reputational power. When the coordination channel breaks, it is the end user who pays the price. She did not endorse Nightmare Eclipse\u2019s public disclosure strategy, and Childs described the July 14 release threat as \u201cunfortunate.\u201d But both experts placed the ultimate blame on Microsoft. \u201cThese vulnerabilities are Microsoft\u2019s,\u201d Moussouris stated flatly. \u201cThey wrote the code. They bear the risk to their customers.\u201d<\/p>\n<p>This is not an isolated incident. Complaints about Microsoft\u2019s vulnerability disclosure process have been accumulating for years. The accelerating use of AI by both blue teams and independent researchers is generating an explosion in vulnerability findings, which is further straining the relationship between reporters and vendors. When a researcher believes all legitimate channels have been closed\u2014an account deactivated, a report unanswered, a bounty denied\u2014the only bargaining chip left is the exploit code itself. The community is now watching whether the July 14 release will contain new, unpatchable flaws, and whether Microsoft\u2019s Digital Crimes Unit will attempt to make an example of a researcher who once believed they were helping.<\/p>\n<h2>Practical Guidance for Windows Users and Enterprise Defenders<\/h2>\n<p>Of the six disclosed vulnerabilities, three have been patched. <strong>BlueHammer<\/strong> was corrected in the April Patch Tuesday cycle. <strong>RedSun<\/strong> and <strong>UnDefend<\/strong> were addressed in the May 21 out-of-band update. Administrators should verify that their Windows Defender platform version is <strong>1.1.26040.8 or later<\/strong>, and that the engine version is <strong>4.18.26040.7 or later<\/strong>. For enterprise environments using WSUS or Intune, manual confirmation of patch delivery status is recommended. <strong>YellowKey<\/strong> has no formal patch. Microsoft has published a mitigation script that can be applied to the Windows Recovery Environment (WinRE), but the primary defense is to change the BitLocker protector policy from \u201cTPM only\u201d to <strong>\u201cTPM+PIN\u201d<\/strong> via PowerShell or Control Panel. This significantly narrows the attack surface, although it does not eliminate the flaw. Physical access is required for exploitation, but stolen laptops and unattended endpoints in enterprise settings remain at risk. <strong>GreenPlasma<\/strong> and <strong>MiniPlasma<\/strong> have no patches available. Defenders must move beyond reliance on a single security product. Network monitoring, identity management, and behavioral detection systems should be verified to function correctly even if Defender itself is compromised. The underlying question for every security stack is whether its other layers can still detect an intrusion when the primary antivirus engine has been silently disabled.<\/p>\n<h2>What the July 14 Release Means for the Industry<\/h2>\n<p>The entire security industry is now waiting for July 14, 2026. The researcher has not indicated the number or severity of the vulnerabilities that may be released. The date is strategically chosen\u2014it aligns with Microsoft\u2019s own Patch Tuesday, a day when security teams are already scrambling to deploy updates. Whether the upcoming release contains ten new flaws or one critical vulnerability affecting a core kernel component, the fundamental issue will remain unresolved. The erosion of trust between one of the world\u2019s largest software vendors and the independent research community that has historically served as an unpaid quality assurance department cannot be repaired with a single blog post or a single patch cycle. Childs\u2019 final observation is the most sobering: \u201cThe entire industry needs to stop and remember there are real human beings on both sides of this equation. When the process fails, the customer gets hurt.\u201d The customers are already hurting, and the process is broken.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The discovery and coordinated disclosure of software vulnerabilities has long relied on a fragile compact between independent researchers and the world\u2019s largest technology companies. In the spring of 2026, that compact has shattered in spectacular fashion. An anonymous security researcher operating under the pseudonym Nightmare Eclipse, also known as Chaotic Eclipse, has publicly released proof-of-concept [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":85259,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/54234.png","fifu_image_alt":"Researcher Unleashes 6 Windows Zero-Days, MSRC Trust Collapses","footnotes":""},"categories":[349],"tags":[],"class_list":["post-54234","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/54234.png","fifu_image_alt":"Researcher Unleashes 6 Windows Zero-Days, MSRC Trust Collapses","fifu_redirection_url":"https:\/\/artic.edu\/artworks\/129607","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/54234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=54234"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/54234\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/85259"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=54234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=54234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=54234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}