CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 437

As cited

Copy frozen at (site build).

vulnerabilities

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Microsoft released patches for two high-severity zero-day vulnerabilities disclosed by a security researcher operating under the pseudonym Nightmare Eclipse. The researcher had previously disclosed multiple vulnerabilities with proof-of-concept code after alleging that Microsoft breached a confidentiality agreement regarding their discussions about security issues. The disclosure dispute highlights tension between the researcher and Microsoft over the terms and handling of vulnerability reporting.

Why it matters: Organizations running affected Microsoft systems should prioritize patching these high-severity vulnerabilities to prevent potential exploitation, especially given public availability of proof-of-concept code.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Microsoft released patches for two high-severity zero-day vulnerabilities disclosed by a security researcher operating under the pseudonym Nightmare Eclipse. The researcher had previously disclosed multiple vulnerabilities with proof-of-concept code after alleging that Microsoft breached a confidentiality agreement regarding their discussions about security issues. The disclosure dispute highlights tension between the researcher and Microsoft over the terms and handling of vulnerability reporting.

Why it matters: Organizations running affected Microsoft systems should prioritize patching these high-severity vulnerabilities to prevent potential exploitation, especially given public availability of proof-of-concept code.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary