Microsoft held two opposite positions in a single week. That is the flaw.
While the industry re-litigates responsible disclosure, a flaw that bypasses BitLocker is still sitting unpatched. And Microsoft, which wrote the rules of the game, just proved it only follows them when the mood takes it.

While the industry re-litigates responsible disclosure, a flaw that bypasses BitLocker is still sitting unpatched. And the company that wrote the rules of the game just proved it only follows them when the mood takes it.
Let's replay Microsoft's week. One day, the company publishes a post that calls any disclosure of a flaw outside its channels "unjustifiable" and waves the threat of criminal prosecution through its dedicated digital crimes unit. A few days later, jeered by the security community, it explains that of course it has no intention of prosecuting anyone and that coordinated disclosure remains its guiding star. Same facts, two opposite positions, seven days apart.
Meanwhile, one of the six flaws in question bypasses the BitLocker encryption of Windows 11 and is still waiting for its patch. We argue about a researcher's manners while an encryption door stays open.
The industry, true to form, immediately replayed its favorite debate, the one about responsible disclosure. Should the researcher have waited. Does Microsoft have the right to threaten. We took sides, we got outraged, we dredged up our worst memories of reporting to the MSRC. And we missed what the sequence really showed.
What exactly happened between Microsoft and the researcher?
Let's rebuild the sequence, documents in hand. On 27 May 2026, Microsoft's security response center, the MSRC, publishes a post that names six flaws disclosed outside its channels, RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma and MiniPlasma, and states that uncoordinated disclosures putting exploit code for unpatched flaws into the hands of malicious actors are "never justifiable." The text adds that its dedicated digital crimes unit will keep bringing cases against those actors and against those who help them, in coordination with authorities around the world.
Three to four days later, under community pressure, the company reframes: it would have "no intention of pursuing legal action against people who conduct or publish security research," the criminal route targeting only whoever "breaks the law and causes real harm" to its customers. Between the two statements, nothing changed in the facts, only the volume of the criticism.
The researcher, who signs as Nightmare Eclipse, claims for their part that Microsoft had cut off access to the MSRC account they used to report these flaws, before pushing them toward publication. A contested version, but it puts at the center of the file the only question that really matters, the one about the reporting channel.
A company that changes its mind in a week has no doctrine
Microsoft is no naive player in disclosure, it is the inventor of it. It was there, in the mid-2000s, that the loaded term "responsible disclosure," which puts the blame on the researcher, was swapped for "coordinated disclosure," which describes a two-party process. Twenty years of practice, a written doctrine, entire teams that keep it alive. The knowledge is there, massive, available.
And at no point did it carry any weight. When six flaws embarrassed the company, it was not that knowledge that spoke up, it was the lawyers. When the community reacted, it was no longer the lawyers either, it was communications. Microsoft's position that week was not dictated by what it knows about security, it was dictated by the last person to shout loudly enough. That is what the sequence reveals, and it is far more worrying than a rude researcher. One of the most mature companies in the sector, called on to defend a line, changed it in seven days. That is not a doctrine, it is a mood.

Which flaw leaves BitLocker open while we argue?
Among the six flaws, only one carries a name that should settle the debate: YellowKey, tracked as CVE-2026-45585, bypasses the BitLocker encryption of Windows 11. That is the door left open, the one that calls into question the at-rest protection of an entire company's drives if an attacker gains physical or local access to the machine.
Three others did not wait for the discussion to end. BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498) were used in real attacks and entered the catalog of actively exploited vulnerabilities kept by CISA, the American cybersecurity agency, the very one Microsoft cites when it blames the researcher for arming attackers. Four flaws out of six, then, with either a missing patch or an exploit already in the wild, while the industry's energy drained into an argument about precedence.
Is the researcher Nightmare Eclipse the real problem?
Let's be clear, I do not absolve Nightmare Eclipse. Publishing exploit code for unpatched flaws, three of which did serve in real attacks before landing in CISA's catalog of exploited vulnerabilities, is nothing like an act of public service. There are victims at the end of it, organizations with no patch and no choice.
But look at what that admission does to Microsoft's argument. Even granting that the researcher acted wrongly, nothing explains why a company of this size responds with a legal reflex one day and a denial the next. The researcher's supposed fault does not manufacture a coherent position for the company. It only reveals that it had none.
The real breakdown is in the plumbing, not in the morals
There was a real subject, though, and no one looked at it. The researcher claims to have first reported these flaws by the book, before Microsoft deleted the account used to escalate them, withheld their bounties and erased their name from a security advisory. True or false in this particular case, it hardly matters. That is exactly where real security is decided, in the state of the channel that connects those who find the flaws to those who fix them. Clog that channel, and all that is left for the researcher is silence or wild publication. Both end up as zero-days.
A disclosure process is not a courtesy reserved for well-mannered researchers. It is a risk-reduction mechanism, with deadlines kept, acknowledgments, payment, attribution. Microsoft knows all of this by heart. It simply chose, under pressure, to defend its reputation rather than fix its plumbing.
The real question was never whether the researcher was responsible. It is how the company that wrote the manual on disclosure could, in a single week, forget that it had written it. On 14 July, the researcher promises a fresh volley. That day we will see whether Microsoft has found a backbone again, or only a new mood.
Sources
- Microsoft (MSRC) post, "A shared responsibility: protecting customers through coordinated vulnerability disclosure," 27 May 2026: microsoft.com.
- Researcher "Nightmare Eclipse," flaw identifiers and real-world exploitation recorded by CISA: TechCrunch, 29 May 2026.
- Microsoft's clarification, details of the six flaws (including YellowKey, CVE-2026-45585, targeting BitLocker) and of the three KEV catalog entries: Cybersecurity News.
- Microsoft backing off its legal threats and the community's reaction: Windows Central.
- Actively exploited vulnerabilities: CISA, Known Exploited Vulnerabilities Catalog.
Frequently asked questions
What are the two opposite positions Microsoft held?
One day, the company calls any disclosure outside its channels "unjustifiable" and mentions prosecution through its dedicated digital crimes unit. Three to four days later, under criticism, it assures that it has no intention of pursuing researchers and reaffirms coordinated disclosure as its guiding star.
Which flaw stays unpatched during this debate?
YellowKey, tracked as CVE-2026-45585, bypasses the BitLocker encryption of Windows 11 and is still waiting for its patch, while the industry argues about the researcher's manners.
What are the six flaws disclosed by Nightmare Eclipse?
Microsoft names them RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma and MiniPlasma. Three of them, BlueHammer, RedSun and UnDefend, were used in real attacks and appear in CISA's catalog of actively exploited vulnerabilities.
Does the article defend the researcher Nightmare Eclipse?
No. The author does not absolve them: publishing exploit code for unpatched flaws, three of which were used in real attacks, is not an act of public service. But that does not explain the inconsistency of Microsoft's response.
Did Microsoft really give up on prosecuting the researcher?
After its post of 27 May 2026, the company clarified that it has no intention of pursuing legal action against people who conduct or publish security research, reserving the criminal route for whoever breaks the law and causes real harm. It is that reversal which, in a few days, reveals the absence of a doctrine.
Why is Microsoft particularly concerned by disclosure?
Microsoft is its inventor: it was there, in the mid-2000s, that "responsible disclosure" was replaced by "coordinated disclosure." Twenty years of practice and a written doctrine that nonetheless carried no weight in its reaction.
What is the disclosure "plumbing" according to the article?
It is the channel that connects those who find the flaws to those who fix them, with deadlines kept, acknowledgments, bounties and attribution. When this channel is clogged (a deleted account, withheld bounties), all that remains is silence or wild publication, which end up as zero-days.
Sources & methodology
- Microsoft MSRC, A shared responsibility: protecting customers through coordinated vulnerability disclosure (
- CISA, Known Exploited Vulnerabilities (KEV) Catalog

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
