V-Help
← All news
Security

GitHub Bans Security Researcher for Windows Vulnerabilities

GitHub Bans Security Researcher for Windows Vulnerabilities

Photo: Tom's Hardware

Quick answer

GitHub заблокировал аккаунт исследователя безопасности Nightmare-Eclipse, обвинившего Microsoft в мести за отказ выплачивать вознаграждения за найденные уязвимости Windows.

Independent security researcher Nightmare-Eclipse (pseudonym Chaotic Eclipse) reported that Microsoft blocked his GitHub account. While the exact reasons remain undisclosed, the expert claims the company deleted his Microsoft account used for submitting vulnerability reports. He has since moved his work to GitLab.

In a blog post, Eclipse accuses Microsoft of retaliation, stating the company not only refused dialogue but also failed to pay promised bounties for disclosed vulnerabilities. Microsoft’s Security Response Center (MSRC) program offers up to 18 млн ₽ for critical vulnerabilities, such as those in Hyper-V. However, the researcher claims he received no compensation despite publishing six Windows exploits.

The situation is further complicated by the fact that some of Eclipse’s disclosed vulnerabilities are already being exploited by threat actors. These include BlueHammer (privilege escalation via Defender), RedSun, UnDefend (Disabling Defender), GreenPlasma (exploiting CTFMon), and YellowKey (bypassing BitLocker encryption). The expert has threatened to release new exploits on July 14, calling it 'retaliation' against Microsoft’s actions.

Other cybersecurity professionals, including William Dormann from Tharros, note that MSRC’s policies have shifted: the company now requires video proof of exploits, and qualified staff have been laid off as part of restructuring. This raises concerns about transparency in vulnerability disclosure and the effectiveness of researcher engagement.

The GitHub account ban has drawn criticism toward Microsoft, as such measures fail to address security concerns and instead exacerbate conflicts. With the time between vulnerability discovery and exploitation shrinking, experts urge companies to rethink their approaches to collaborating with researchers.

Common questions

Почему GitHub заблокировал аккаунт Nightmare-Eclipse?
Microsoft заблокировала аккаунт исследователя безопасности Nightmare-Eclipse на GitHub, обвинив его в мести за отказ выплачивать вознаграждения за обнаруженные уязвимости Windows и игнорирование отчетов.
Какие уязвимости Windows нашел Nightmare-Eclipse?
Исследователь обнаружил и опубликовал несколько эксплойтов, включая BlueHammer, RedSun, UnDefend, GreenPlasma и YellowKey, которые позволяют получать права SYSTEM, отключать Defender и обходить шифрование BitLocker.
Почему Microsoft не выплатила вознаграждение Nightmare-Eclipse?
Nightmare-Eclipse утверждает, что Microsoft не выплатила обещанные вознаграждения за шесть обнаруженных эксплойтов, несмотря на программу MSRC, предусматривающую выплаты до 18 млн ₽ за критические уязвимости.
Какие последствия может иметь блокировка аккаунта для кибербезопасности?
Блокировка аккаунта Nightmare-Eclipse вызвала критику в сообществе кибербезопасности, так как подобные меры не решают проблему безопасности, а лишь усугубляют конфликт и могут замедлить процесс раскрытия уязвимостей.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: Tom's Hardware