
Microsoft backs coordinated vulnerability disclosure after researcher’s zero-day spill
Microsoft pressed for Coordinated Vulnerability Disclosure after Chaotic Eclipse exposed multiple Windows zero-days (BlueHammer, RedSun, UnDefend, YellowKey, among others), with several exploits already in the wild. The company says uncoordinated disclosures risk customers and impeded timely fixes, while promoting dialogue within the security community. GitHub reportedly removed the researcher’s account amid the flare-up, and exploit code briefly appeared on GitLab before the account was blocked. The researcher has warned of a July 14, 2026 release, signaling ongoing tensions between researchers and vendors over disclosure practices.





