Security News

Cybersecurity news aggregator

HIGH Vulnerabilities Ars Technica Security

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

Microsoft has patched a high-severity zero-day vulnerability disclosed by researcher Nightmare Eclipse, who released proof-of-concept code after alleging Microsoft reneged on a prior agreement. The article does not provide the specific attack vector, CVSS score, affected software versions, fixed version numbers, or a workaround for this security update.
Read Full Article →

Microsoft on Tuesday released a fix for a high-severity zero-day that was disclosed by a researcher who has been locked in a testy beef with the software giant. A separate zero-day also appears to have been patched. Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-days that had the potential to be exploited in the wild. The researcher has said the disclosures, which included proof-of-concept code, came after Microsoft reneged on an arrangement the two made regarding vulnerabilities they had discussed. Disclosure drama “But someone violated our agreement and left me homeless with nothing,” Nightmare Eclipse wrote in March. “They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.” Read full article Comments

Share this article