Microsoft criticizes uncoordinated disclosure of six zero-day vulnerabilities
Right out the toaster. Reliable, with some real depth.
Summary
Microsoft has criticized the irresponsible disclosure of six zero-day vulnerabilities in its products, named BlueHammer, GreenPlasma, MiniPlasma, RedSun, UnDefend, and YellowKey. The proof-of-concept exploits were published without prior coordination with Microsoft, leaving its security teams unprepared. Microsoft emphasized its commitment to Coordinated Vulnerability Disclosure (CVD) processes, which allow ethical sharing, patch development, and researcher recognition. The company stated its teams work hard to address vulnerabilities but were caught off guard by these uncoordinated releases.
Key quotes
· 3 pulledMicrosoft said the disclosures were not responsibly handled and were released without warning, leaving its security teams unprepared.
Microsoft stated it uses Coordinated Vulnerability Disclosure processes each year with many security researchers to enable ethical sharing, patch development, and recognition of researchers.
Microsoft said its teams work hard to address vulnerabilities but were caught off guard by these uncoordinated releases.
You might also wanna read
Anonymous researcher releases two new Windows zero-day exploits after Patch Tuesday
An anonymous security researcher (Nightmare-Eclipse/Chaotic Eclipse) has released two new Windows zero-day exploits — YellowKey (a BitLocker
Security researcher publishes YellowKey zero-day exploit that bypasses Microsoft BitLocker encryption via USB stick
Security researcher Chaotic Eclipse (Nightmare-Eclipse) has published two new zero-day exploits targeting Microsoft systems after their prev
CVE-2025-53136: Microsoft Patches Windows Kernel Information Disclosure Vulnerability Bypassing KASLR
Microsoft patched CVE-2025-53136, a kernel information disclosure vulnerability in Windows NT OS Kernel that allowed leaking kernel base add
Critical Misconfiguration in Microsoft's Internal Applications Exposes Sensitive Data
The article details a security researcher's discovery of a critical misconfiguration in Microsoft's internal applications, which allowed una
research.eye.security·9mo agoBlueHammer abuses Windows Defender's update process to gain SYSTEM access
Google Project Zero Addresses the 'Patch Gap' in Vulnerability Disclosure
The article discusses Google Project Zero's updated vulnerability disclosure policy, the '90+30' model, introduced in 2021 to accelerate pat
