After a security researcher published exploits for unpatched Microsoft flaws, the software King of the world has called the cops.
The researcher, going by the handle “Nightmare Eclipse,” disclosed a series of vulnerabilities, including BlueHammer, RedSun, UnDefend, and YellowKey. These affected core Microsoft products like Defender and BitLocker.
Vole’s main gripe is that the researcher went public before giving the company a chance to patch the bugs, calling responsible disclosure “the proper way” to handle vulnerabilities.
Publishing exploits publicly may have helped malicious actors, Microsoft claims. The company says some of these flaws have already been leveraged in real-world attacks. The US cybersecurity agency, CISA, has noted attacks linked to the disclosed vulnerabilities, amplifying the stakes for Microsoft.
“Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity — coordinating as needed with law enforcement around the world,” the company wrote.
Vole’s Digital Crimes Unit uses a mix of civil legal action, technical countermeasures, criminal referrals, and public-private partnerships to protect its products and customers.
Nightmare Eclipse claims they attempted to communicate with Microsoft before going public but felt rebuffed and mistreated, including having their access revoked.
The dispute raises long-running questions about the responsibilities of security researchers, particularly when reporting to massive tech companies with deep pockets. Some experts argue that public disclosure of vulnerabilities, even before patches exist, forces companies to act faster and improves overall security.
Others caution that exposing exploits without protective measures simply hands hackers a roadmap to attack systems.
Nightmare Eclipse says its goal was to highlight security issues and pressure Microsoft to address gaps quickly.
Tech industry commentators note that legal threats against researchers can chill disclosure, potentially leaving serious bugs in the wild for longer. Microsoft insists that coordinated disclosure provides a safer path for companies and users, giving defenders time to patch systems before exploits hit the wild.
According to Techcrunch cybersecurity analysts have mixed views. Some call the researcher’s method reckless; others say Microsoft’s response is heavy-handed.
Nightmare Eclipse has not been arrested but could face lawsuits or criminal referrals, depending on how authorities interpret the disclosures.
Security researchers warn that future disclosure behaviour could change if companies respond with aggressive legal threats rather than collaboration.







