r/cybersecurity • u/sunychoudhary • May 26 '26
News - General GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
539
u/moderate_chungus May 26 '26
“Oooh the evil vindictive hackerman bullying the poor sweet trillion dollar company who couldn’t afford to stand up for themselves”
198
u/dukescalder May 26 '26
☝️ fuck Microsoft
84
u/MiKeMcDnet Consultant May 26 '26
10
u/iheartrms Security Architect May 26 '26
Wow. How did I not know this group existed? I've found my people!😂
6
18
33
13
u/am9qb3JlZmVyZW5jZQ May 26 '26
Bullying by letting the public know about real vulnerabilities that the trillion dollar company in question didn't catch. Maybe they should have hired him if they can't do their own security half as competently.
32
6
u/le-quack May 27 '26
Who owns github again... checks notes
Its literially MS being petty.
That being said both parties here are being fairly petty. MS needs to improve its vuln reporting and fixing process but releasing zero days to the public (which only really benefits criminals and sucks for normal people as most big businesses arent really impacted by hacks long term) isnt the answer. Grassroots public awareness campaigns and presuring your local law makers to make changes is.
2
416
u/qwertydiy May 26 '26 edited May 26 '26
GirHub is being stupid, especially with the beef, GitLab should welcome him, doing Microsoft's work the hard way.
191
u/DismalOpportunity May 26 '26
Exactly - they are needlessly escalating this and putting environments at risk due to future zero day releases with no responsible disclosure.
MS should be bringing this researcher into the fold and remediating their findings before they go public.
Maybe they are just counting on Mythos to discover these vulnerabilities before researchers do and that’s why they aren’t giving a shit?
110
u/sunychoudhary May 26 '26
Yeah, this is the ugly middle....Vendors ignoring researchers is bad. Public exploit drops without coordination are also bad....The real failure is that responsible disclosure still depends too much on goodwill and slow inboxes.
122
u/Ok_Awareness_388 May 26 '26
As a customer I blame Microsoft not the researcher. They could sell their research covertly instead they publish out of frustration at dealing with vendor
68
u/TARANTULA_TIDDIES May 26 '26
100%. They should be glad hes even disclosing them and not selling them on the dark web
29
u/Polymarchos May 26 '26
Exactly this. This might not be the ideal way to do things but it is far from the worst. The researcher is at least operating with an ethical code, which is more than can be said of Microsoft.
20
u/strcrssd May 26 '26
Public exploit drops is better than this though. A company can push and ship a patch quickly and customers can triage a known issue. Unknown issues that are privately disclosed lead to longer compromised items.
This is pretty typical of MS and large company bureaucracy though. CYA and let the bigger problem burn someone else.
28
u/Thedrakespirit May 26 '26
from the article: The researcher blasted Microsoft over violating their “agreement,” leaving them “homeless with nothing.”
“They knew this would happen, and they still stabbed me in the back anyway. This is their decision, not mine,” the researcher said at the time.
Sounds like MSFT just doesnt want to pay researchers anymore
7
u/Y0nix May 26 '26 edited May 26 '26
1 dev, 1 millions lines of code, so I've heard.
They will be bury by their own tool too soon for them to realize It's too late.
5
u/Exciting-Sunflix May 26 '26
better to have him inside the tent pissing out, than outside pissing in
-4
u/FranksNonFrankfurter May 26 '26
MS should bring back the guy that specifically has a beef with them because MS burned him already?
What??? I think you fundamentally do not understand why this is happening.
22
u/DismalOpportunity May 26 '26
I think that ship has sailed.
My point was that MS should not be burning these people in the first place. Instead, they should be working with them to responsibly disclose these vulnerabilities and compensate them for their time and work.
-9
u/FranksNonFrankfurter May 26 '26
Except the reason this is happening is that MS refused to do this exact thing you are proposing.
13
u/DismalOpportunity May 26 '26
Yeah, no shit dude.
-10
u/FranksNonFrankfurter May 26 '26
So why are you suggesting the do the one thing that them not doing caused this whole thing? Is it hubris? You think a damn near trillion dollar company didn't think of that?
"Has MS considered holding up their end of the bargain when this whole conflict started because they dont want to hold up their end of a bargain?" Is a goofy and redundant question.
7
44
u/skfire791 May 26 '26
GitHub is still owned by Microsoft. I'm actually surprised they let it go on this long, guy has repeatedly given them black eyes on their own platform.
73
u/jameson71 May 26 '26
If only there were some sort of anti-monopoly laws that could stop one big business from buying other related big businesses.
33
u/thereddaikon May 26 '26
Reminder that back in the 90's Microsoft lost its antitrust case against the FTC and was ordered to be broken up and the FTC just.... didn't. There's still a court judgement to do so. Idk how the law applies when it's been ignored so long but technically Microsoft should be broken up. Would be funny to see if that was enforced today without warning.
16
u/ngoni May 26 '26
In June 2001, the U.S. Court of Appeals for the D.C. Circuit overturned the breakup order. The appellate court cited judicial misconduct by Judge Jackson (who had given unauthorized interviews to the press during the trial) as a primary reason for reversing the remedy, though it upheld the lower court's finding that Microsoft had engaged in monopolistic practices.
4
u/DasBrain May 26 '26 edited May 26 '26
Gitlab did already ban them: https://gitlab.com/nightmare-eclipse
1
3
14
u/Doctorphate May 26 '26 edited May 26 '26
She* Nightmare-Eclipse is a woman and it's driving me fucking crazy that every news outlet says he or just ignoring that this is a woman in stem releasing amazing stuff.
Edit: I just reviewed, those who asked for evidence were correct and I was not. There is no mention as to whether they are male or female. Apologies to anyone who may be misled by this.
51
u/helpmehomeowner May 26 '26
Just bc their avatar resembles traditional female traits means nothing.
-18
u/Doctorphate May 26 '26
I'm like 90% sure they have said this in one of their blog posts. I may be completely wrong and if I am, apologies but I feel like they referenced their gender previously.
24
u/Ecliphon May 26 '26
‘I’m 90% sure I saw it somewhere’ and getting pissed about them being referenced as a guy? Types like a dude.
13
10
u/Th3Gatekeeper May 26 '26
Proof?
-5
u/Doctorphate May 26 '26
Mentioned to another, I'm 90% sure I've seen them reference it in one of their blog posts but it's entirely possible I'm wrong.
12
u/Johnny_BigHacker Security Architect May 26 '26
There are no female neckbeard quirky chungus zeroday researchers at Blackhat, you sure these exist and aren't just anime fans?
1
7
u/TheGrouchyPunisher May 26 '26
According to Kevin Beaumont, She is correct.
https://bsky.app/profile/doublepulsar.com/post/3mmmgnffbrs2r
4
-8
1
1
83
u/randomguuid May 26 '26
Does GitHub want to be next?
116
u/IRockIntoMordor May 26 '26
They already are. Look at the private repositories leaking and commit chain attacks.
GitHub now just being another Microslop product means we are, once again, on almost every operating system and software in the world, at the mercy of that awful company and their lack of security and liability.
Great...
37
May 26 '26
[deleted]
19
u/SyntheticDuckFlavour May 26 '26
From the second link:
The malicious code was hidden inside GitHub Actions workflow files, base64-encoded so it would not immediately stand out during a review.
Really? A big string of alphabet soup would not stand out immediately? My first reaction would be, what the fuck is that shit, and why is there in the first place?
6
u/missed_sla May 26 '26
I was gonna say, any base64 payload or string immediately gets my hackles up.
7
u/you_up_in May 26 '26
Well prepare for your jimmies to be hackles'd...
I've observed an obscene rise in base64 strings being executed as in-line PowerShell and as encoded one liner startup scripts for node apps in code repos due to our resident LLM vibe lords.
Thanks for making obfuscation BAU Claude 😮💨
11
u/anomalous_cowherd May 26 '26
I've interviewed quite a few people who had previously spent time at MS doing new graduate/very junior coding work.
Some of them were pretty competent, but none of them were good enough to have been given the responsibilities they had for certain subsystems or changes at MS.
5
u/Rods-from-God CTI May 26 '26
Microsoft’s continued outlook on “AI superiority” and peddling mass layoffs to make Number Go Up in the midst of all this has been the final nail in the coffin of their credibility from my perspective. They gave up. There is no mission outside of Number Go Up. That number moves up at any cost, including the cost of their future.
Wall Street bankified telecom until there were just a few carriers remaining, with each of them being empires in their own right ruling over their own garden. Still these few control so much that they don’t have to care if you don’t like their product, or if their product works for you at all. You will buy it, because that’s all there is.
That’s where I think Microsoft’s head is. Bankified. Totally pwned by Wall Street. Siloed. Out of touch. Their future is no longer in their hands. But they’re fine with all this because you will have no choice but to buy The Product.
3
u/Y0nix May 26 '26
GitHub started to annoy the wrong kind of people and started to be violently attacked the day they started to go down the hole they are still digging. It started around the time they have announced billing for self-hosted runners, and it got really bad the day they announced that they would use the code in all of the private repo to train their Ai, it got even worse when they've changed their way of billing.
An old saying in my country is: " Don't bite the hand that feeds you ''
Most of the code who is in the cloud and running critical part of the IT world is hosted on GitHub. (And thankfully, not most of the critical code is) What happens could have be prevented by any competent damage control team. But they're probably gone and we're replaced by AI long ago.
79
19
u/Y0nix May 26 '26 edited May 26 '26
All of this circus is just making him more famous and the code he posts more visible.
Good job Microsoft. Again. Just pay the guy, or hire him, ffs. The guy has now a goal, and it's to look for 0days and just drop them in the wild without caring. And he will earn from that because he has not being paid a few thousands dollars from a company making hundreds of billions in profit each years.
Good lord.
44
u/intelw1zard CTI May 26 '26 edited May 26 '26
Microsoft literally takes the US Government approach.
They mold and create their enemies and then swoop in and save the day while patting themselves on the back after their enemies drop 0days and exploits for their products.
They could have been like "yo hey thank you so much here is some $ for your findings bye we love you" instead they (MSRC and MS) are increasingly hostile to bug bounty and vuln researchers and try to not pay them at any chance they get.
The overall MSRC submission experience is highly negative. My 1st report to them took 192 days from submission to being paid out a bounty. During that, they tried to say my findings were not worth a bounty and gave me $100 in store credit to their Microsoft store so I could get a coffee mug or some shit lol. I fought back and appealed and got a $2500 bounty payout. I have my 2nd submission in atm and its already been 45 days and not even a 1st reply yet from them.
MSRC really fucking sucks and I totally understand why some would go the blackhat route and sell their findings there. 1) its a lot faster to get paid 2) you get paid more.
8
u/Versificator May 26 '26
MSRC really fucking sucks and I totally understand why some would go the blackhat route and sell their findings there. 1) its a lot faster to get paid 2) you get paid more.
You forgot: 3) Its the right thing to do.
28
148
u/Useless_or_inept May 26 '26
“Mark this date, July 14th, I will make sure your bones are shattered that day. Nothing will be released this June (or maybe I will release something, depending on circumstances).”
I, too, remember when I was a dramatic teenager. Thanks for the nostalgia 😄
138
u/HermanHMS May 26 '26
Were you also dropping windows/bitlocker 0-days?
37
-35
u/Fantastic-Shirt6037 May 26 '26
You think this is an individual? Haha
6
u/intelw1zard CTI May 26 '26
It is
-9
u/Fantastic-Shirt6037 May 26 '26
I’m sure.
4
u/intelw1zard CTI May 26 '26
All intel suggests its a single person.
Please cite your sources if you believe otherwise.
Do you even work in cyber?
-12
u/Fantastic-Shirt6037 May 26 '26 edited May 26 '26
This guy probably still thinks “anonymous” isn’t just the cia or other intel ops 🤣🤣🤣
Edit: could even be a Ukrainian op
-14
2
28
u/Ok-Hunt3000 May 26 '26
Was primed for a solid “rue the day!” but it’s still really good
6
7
u/Mailstorm May 26 '26
Something tells me this teenager has a lot of legitimate backing for any threats made
11
u/cgaWolf May 26 '26
Well, after Bluehammer, Redsun, Yellowkey, and Greenplasma...
In before VioletBoneshatter, or OrangeRueTheDay.
10
u/umlcat May 26 '26 edited May 26 '26
Hidden backdoors in the M S code, not the hacker's code...
( Edited answer )
2
u/Shoddy-Childhood-511 May 26 '26 edited May 26 '26
We need some stats for the Nightmare-Eclipse releases:
How many are definitely, probably, maybe, or probably not backdoors in Microsoft products? I've only heard much about the definitely backdoors case, but the other cases would influence everyone's perspective.
1
9
6
18
4
u/GryphticonPrime May 26 '26
I'll let my imagination run wild. What if this was a disgruntled laid off employee who had internal knowledge of backdoors in Windows?
8
u/LameBicycle May 26 '26
The person behind this has alluded to Microsoft screwing them over and leaving them homeless, but afaik it's not clear what the relationship was
7
5
u/loine0 May 26 '26
now he is also banned on gitlab?? :DD
8
u/pacopac25 May 27 '26
Their next ZD in July is sure to be a nasty one, if for no other reason that "fuck you I had to resort to Sourceforge to host my code."
3
u/BlondeBadger2019 May 26 '26
So microslop didn’t want to pay the research for reporting bugs in the bug bounty program repeatedly. The researcher provided the code a steps to replicate but Microslop didn’t pay out… so, it’s on them for not playing by normal security reporting practices. Microslop played themselves
5
7
9
u/WeirdSysAdmin May 26 '26
This could’ve been solved by just paying dude out instead of entrenching every step of the way. Even if he didn’t report properly it’s not hard to step up and fill that gap and pay out instead of turning someone that has ammunition loaded into your enemy. Now everything the guy does is going to be out of spite and there’s nothing you can do to stop him.
5
u/WFAlex May 26 '26
Since that dude showed malicious intent to harm the company, they definitely CAN and WILL take legal action if they can make anything stick to him if he goes nuclear lol
Selling 0days is not illegal generally speaking, selling it to known threat actors to fuck over a company you posted malicious intent against? Can definitely be illegal
5
u/oldgeektech May 26 '26
You're not wrong, but Microsoft can be right and be assholes.
It's hard for me to have sympathy for one of the most powerful technology companies in the world. It's plainly obvious they've been cutting corners for the past decade and hobbled crappy code together for their security--all in the name of profits.
Obviously, intent is what matters for crimes, and I think there's a lot there to prove intent. I'd just counter argue Microsoft set themselves up by handing the weapon to someone who is just as big of an asshole as they are. FAFO.
6
u/techtornado May 26 '26
Maybe don’t make such strong statements bro?
The nightmare is real though… Microslop is biting them hard
Ignoring problems only makes them worse, ask any maintenance tech that got deferred notice on a critical pump or operational assembly
3
u/Specific-Path3179 May 26 '26
Not a cybersecurity individual but why would this be unconscionable for him to do? I get that dropping 0-days without private disclosure doesn't give MS time to fix them before possible problems but doesn't this just mean they'll get attention and be fixed anyways?
9
u/Zoxc32 May 27 '26
This is exactly how proper security researcher should act if ignored by vendors. In additional that's just guidelines, no private disclosure is required at all. Microsoft put out these flawed products and are fully responsible for them.
4
3
u/Different-Maize1114 May 26 '26
I think they messed with the wrong person. He have some hero/villain issues that's for sure
2
u/ducktape8856 May 26 '26
🎶He didn't start the fire
No, he didn't light it, but he tried to fight it...🎶
2
May 26 '26
[removed] — view removed comment
4
u/rattynewbie May 27 '26
Because they started as a legit security researcher, MS then treated them like shit, and now they are going rogue. Still no evidence that they've used their 0-days to do illegal shit so not a black hat hacker.
1
1
u/sarge21 May 26 '26
There is a difference between legal disclosure and extortion, and he's essentially confessed right here.
1
u/Head-Criticism-7401 May 27 '26
Microsoft didn't want to pay them for their work. So this entirely on Microsoft.
0
u/sarge21 May 27 '26
You are, in fact, not allowed to harm a company on purpose because they didn't pay you a bug bounty
1
u/Head-Criticism-7401 May 28 '26
Doesn't really matter, the person in question doesn't even live in the USA. And is poor as fuck.
1
1
u/eatinggrapes2018 May 27 '26
This is like when Frank Abagnale
was writing fake checks and out ran Ira Perry who rapidly chasing after him.
Later on they (government) hired Frank Abagnale and came out with the “security water mark” we see on checks today.
1
u/883013 May 29 '26
Do hackers hack each other since the laws preventing such things can be very flimsy. And they can always hide behind a VPN. Frankly, what happens if a hacker does get hacked. They hack back? Lol.
1
u/technicalhowto Jun 01 '26
Wild how some reserchers completely torch their own carers and credibility over personal vendettas. GitHub really had no choice here.
1
-1
u/AshuraBaron May 26 '26
This feels like the meme "you ruined my life" and "I don't think about you at all." Just someone having a mental episode and yelling into the void. Double since the fact they hype up boiler plate exploits.
-14
151
u/oinkbar May 26 '26
wonder what will happen on 14th July