Microsoft said multiple Windows zero-day vulnerabilities were publicly disclosed without prior coordination, exposing customers before patches or mitigations were ready. The company identified the flaws as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma, affecting components including Microsoft Defender and BitLocker, and said the releases undermined Coordinated Vulnerability Disclosure practices by giving attackers technical details and proof-of-concept material to weaponize. Microsoft said its security teams are assessing impact, developing updates, and continuing to accept reports through the Microsoft Security Response Center.
The disclosures were tied to researcher Chaotic Eclipse, also known as Nightmare-Eclipse, whose GitHub account was reportedly removed and whose GitLab account was later suspended after exploit tools were mirrored across platforms. Reports said BlueHammer (CVE-2026-33825) was patched in April and added to CISA’s Known Exploited Vulnerabilities catalog, while RedSun and UnDefend remained unpatched as of late May; Microsoft and outside researchers said BlueHammer, RedSun, and UnDefend were already being exploited in the wild, including in intrusions that began with compromised FortiGate VPN credentials and escalated through Defender flaws. The researcher has accused Microsoft of mishandling earlier communications and threatened another public release, deepening the dispute over vendor coordination and platform enforcement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Reporting said Nightmare-Eclipse threatened or announced another disclosure event for 2026-07-14. The planned release was described as a further escalation in the dispute over Microsoft’s handling of vulnerability disclosures.
Microsoft released a patch on 2026-06-09 for CVE-2026-45586, a high-severity Windows local privilege escalation zero-day in the Collaborative Translation Framework that had been publicly disclosed by Nightmare Eclipse. The same patch cycle also appeared to fix the researcher-disclosed MiniPlasma issue, although Microsoft did not explicitly confirm that in its advisory.
In late May 2026, Microsoft issued a clarification after backlash over its earlier comments on Nightmare-Eclipse, saying it did not intend to pursue action against individuals conducting or publishing security research in good faith. The company said legal escalation would be reserved for unlawful, malicious activity that causes real harm to customers and reaffirmed its vulnerability disclosure portal and coordinated disclosure stance.
Microsoft publicly criticized Nightmare Eclipse for releasing unpatched vulnerability details and exploit code, and warned that its Digital Crimes Unit could pursue legal action and coordinate with law enforcement. The warning escalated the dispute over the researcher’s disclosures beyond Microsoft’s earlier public criticism.
In May 2026, the researcher Nightmare-Eclipse was suspended by GitHub and GitLab after publicly releasing and mirroring Windows zero-day exploit tools. Separate reporting said GitHub removed the account first and a subsequent GitLab account was also blocked.
After BlueHammer was patched, it was added to CISA’s Known Exploited Vulnerabilities catalog. This reflected official recognition that the flaw had been exploited in the wild.
BlueHammer, tracked as CVE-2026-33825, was patched by Microsoft in April 2026. The same reporting said RedSun and UnDefend remained unpatched as of May 2026.
On 2026-05-27, Microsoft said several zero-day vulnerabilities, including RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma, had been publicly disclosed without prior coordination. The company said it was investigating impact, protecting customers, and developing security updates while reaffirming coordinated vulnerability disclosure practices.
By 2026-04-10, Huntress Labs reported active exploitation of BlueHammer, RedSun, and UnDefend in the wild. The activity included attackers entering through compromised FortiGate VPN credentials and then using Defender exploits for privilege escalation.
The public release campaign by the researcher known as Nightmare-Eclipse reportedly began on 2026-04-02 after dissatisfaction with Microsoft Security Response Center handling of disclosures. The campaign included BlueHammer, RedSun, and UnDefend exploit tools targeting Microsoft Defender.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcecyberscoop.com
Open sourcexakep.ru
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcecybersecuritynews.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.