6 ms·
GitHub bans security researcher who posted zero-day Windows exploits
- jrflowers 4mo ago> forcing them to pack up and move shop to GitLab instead. https://gitlab.com/nightmare-eclipse https://gitlab.com/nightmare-eclipse Blocked user @nightmare-eclipse Looks like they’re banned on GitLab as as well?
- parliament32 4mo agoI suspect MS threatened them with a SmartScreen blackhole for the domain, I'm not surprised they pulled it.
- josephg 4mo agoI don’t like the idea Microsoft can bully other websites into blocking content they don’t like.
- akerl_ 4mo agoDo we have any evidence they did that other than the comment you replied to speculating?
- keepupnow 4mo agoYes they definitely did that. Find evidence to the contrary.
- deleted 4mo ago[deleted]
- no-name-here 4mo agoIs this sarcasm? Or are you saying that the onus of providing proof is not on the those making the claim, but instead that the onus of proof is on those who did not make the claim?
- snvzz 4mo agoSure you can provide an alternative explanation? Otherwise, that's the best we have.
- no-name-here 4mo ago> Sure you can provide an alternative explanation? In terms of a possible explanation for why GitLab would take an action, was it considered whether the (disturbed?) user violated GitLab's Terms of Service? Is the assumption that GitLab didn't just enforce their ToS, but that they're instead more likely to be secretly acquiescing to backroom bullying between companies over specific users?
- akerl_ 4mo agoIt seems clear that the Bitbucket devs paid bribes to Gitlab to ban this user to drum up anti-GitHub sentiment.
- baobabKoodaa 4mo agoYou don't need to be Sherlock Holmes to draw that conclusion.
- Aurornis 4mo agoAre there any copies of what he supposedly posted? I have a hard time believing someone posted groundbreaking exploits to two separate Git websites and not a single person cloned them. I also think it’s funny that people are alleging .gov conspiracies that end in a publicly hosted “blocked user” page instead of just 404-ing or something.
- jwitthuhn 4mo agoForks are still alive on github, so it seems unlikely microsoft did this to suppress the code. Unless they are wildly incompetent, which I don't want to outright reject as a possibility. https://github.com/xiaoji235/bitlocker-bypass-tool-for-winre https://github.com/xiaoji235/bitlocker-bypass-tool-for-winre Unfortunately I don't think there is any way to see a list of all the forks now that the main repo is dead, but you can search the phrase "A huge thanks to MORSE, MSTIC and Microsoft GHOST for making this public disclosure possible" to find more copies.
- cortesoft 4mo agoResearcher seems a bit unhinged.
- ryukoposting 4mo agoTakes a certain kind of crazy to pay your bills with bug bounties.
- Animats 4mo agoThat may go with the task of looking for low-level security holes.
- xeonmc 4mo agoOr being forced into homelessness by Microsoft
- stainablesteel 4mo agosanity isn't his job
- Rotdhizon 4mo agoThis often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.
- lynndotpy 4mo agoSandboxEscaper is still alive, but yeah, Eclipse's prolific vuln dropping reminds me of her.
- huflungdung 4mo ago[dead]
- 4mo ago
- 0cf8612b2e1e 4mo agoSurely, the public string of exploits means he can find gainful employment from any of the various spooks?
- ndiddy 4mo agoI know quite a few extremely skilled people who aren't employed in a technical field. Usually it's some combination of not working well with others, lack of formal credentials and the means to acquire them, or a criminal record. Government work also means you have to be morally okay with what the government does (or willfully ignorant), able to pass a background check, and be willing to go through the security clearance process.
- throwaway85825 4mo agoPeople with skills/means don't want to live in the cheap city/suburb where they have offices. Work from home obviously isn't a thing.
- lstodd 4mo ago"People with skills" just don't care for corporate or government bullshit. You may know them as "not being employed in a technical field", but it's just because you got filtered out.
- deleted 4mo ago[deleted]
- stackghost 4mo agoGovernment work also usually means relocating. The money wouldn't be good enough for me to uproot my family.
- bigfatkitten 4mo agoNot if they can’t gain or maintain a security clearance.
- __d 4mo agoShoot the messenger. That’ll fix it.
- subscribed 4mo agoMaybe they want to incentivise selling exploits to nation states, not patching them?
- bitbasher 4mo agoI can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.
- akkartik 4mo agoNot to mention all the other people who find 0-days. Reputation matters a lot.
- mapontosevenths 4mo agoYep, and its a really small world out there. If researchers stop believing MS will treat them fairly it's bad news for the entire security industry.
- SXX 4mo agoWell. Its a bad news for society as whole. Security industry going to be okay - someone will always pay for 0-days. If vendors wont pay its just gonna be US agencies, Israel resellers, China or Russia. If you don't feed your army, you will soon feed someone's else's.
- rurban 4mo agoIt's had bad news only for Windows buerocrats. Good orgs don't use Windows.
- mapontosevenths 4mo agoI have now worked for/with a significant percentage of the fortune 500. All used Windows in some capacity. Is this just your way of saying that only tiny, weird, companies are "good"?
- hparadiz 4mo agoThese days corporate security treats these workstations like a dummy terminal. No secrets live on the workstation. You have to re-auth with sso constantly with biometrics and are basically editing data that is in a cloud. So the risk to a corp is minimal where even in the worst case they are insured. Zero days like this are being disclosed regularly so the idea of securing a windows workstation is tantalizing but you'll never feel satiated trying to drink that water so don't even try. So yea there's plenty of windows users but we're certainly not hosting anything important on those boxes and would frankly be aghast at the suggestion.
- SXX 4mo agoThis is such a bad idea and what the point anyway? Once 0-day is out its out. Almost like trying to censor leakef HDCP key.
- MiscIdeaMaker99 4mo agoThe optics don't look good for Microsoft, but we don't know their side of the story.
- SXX 4mo agoIt doesnt really matter. Banning someone GitHub account change literally nothing and its another proof Microsoft is not to be trusted as steward of open source platform.
- throwaway85825 4mo agoWorse, cant be trusted to have secure products.
- thewebguyd 4mo agoThey lost the trust of having secure products a long time ago. Windows is directly responsible for the rash of varying quality EDR & other "security software" for endpoints. I mean it took them until Windows 10 to move font rendering out of Ring 0, you could run malicious code in kernel space from a freaking font on a web page at one point.
- SXX 4mo agoAlso recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-as-30percent-of-microsoft-code-is-written-by-ai.html https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...
- throwatdem12311 4mo ago“Recently” this was a year ago - it’s probably more like 95% now
- SpicyLemonZest 4mo agoI think you're going down a bad route when you start inserting gratuitous insults into your summaries of what other people said.
- lynndotpy 4mo agoI disagree with policing someone elses language like this in the first place, but it's only one insult and it's just "Microslop".
- SpicyLemonZest 4mo agoI don't think you should insert any number of insults into summaries of what other people said. It serves no purpose other than degrading the quality of discussion. If someone posted this comment: > Satya Nadella says as much as 30% of Microsoft code is written by AI. More like Microslop, haha! we'd all recognize that the last sentence is pointless name-calling (and thus violates the HN guidelines). But by interleaving the insult, it's easy to trick oneself into thinking that it's meaningful commentary. The quality of HN as a discussion forum requires holding ourselves to a higher standard than that.
- keepupnow 4mo agoIt isn't name calling its a fact. Their software was and now increasingly F grade quality. Microslop.
- pslab 4mo ago[flagged]
- sorry_outta_gas 4mo ago[dead]
- embedding-shape 4mo agoIs there any public word from Microsoft about what is going on here? Why would both Microsoft and Gitlab ban the user? I thought both platforms allowed hosting exploits and security research as long as everything is clearly marked up-front, I'm guessing some rules were broken?
- amusingimpala75 4mo agoWell if it’s a full disk encryption exploit that still requires hardware access I imagine it would have been made for a 3-letter govt org or something
- halJordan 4mo agoThe fde encryption exploit is only for volumes that auto decrypt anyway. So it's a know (accepted) that the model doesn't really try to avoid. You guys need to stop reaching for conspiracy
- throwaway85825 4mo agoWhich is all of them that don't require a pin (rare).
- snvzz 4mo agoFDE is meant to protect data at rest. Hardware access is a given.
- mapontosevenths 4mo ago[flagged]
- hedora 4mo agoUsually, when intentional backdoors like that get found and fixed, the 'someone else' stays silent. Otherwise, they provide proof that they've been planting backdoors, and that's much worse than having a hole plugged. To get an idea of how this stuff usually works, start with the Simple Sabotage field manual: https://ia601309.us.archive.org/14/items/Simplesabotage/Simplesabotage.pdf https://ia601309.us.archive.org/14/items/Simplesabotage/Simp...
- alex1138 4mo agoBasic conflict of interest stuff MS owns GH. It's tonedeaf and criminal
- yuye 4mo ago>It's tonedeaf and criminal Hasn't that been their MO since the start? Absolutely scummy company.
- zuzululu 4mo agoWhat's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.
- technion 4mo agoThe researcher's own statements note that the zero days were not found with AI. And honestly I think that's the part that Microsoft is most upset about, because every internal partner conversation I've had has been about needing to buy Security Copilot because all the advanced attacks are coming from AI, and just suggesting vulnerabilities existed before AI seems to make salespeople uncomfortable continuing the conversation.
- beej71 4mo ago> They seem to have a personal vendetta against Microsoft Probably because they were forced to use MS-DOS when so many better options were killed off by Microsoft's monopolistic and anti-consumer underhanded business tactics... I might be projecting.
- lstodd 4mo agoI was forced to use ms basic on my c64. Never forgive, never forget.
- selcuka 4mo agoI always found it weird to ship a BASIC interpreter that didn't have specialised commands (unless you count POKE) to access the graphics and sound capabilities of a computer like the C64. Some computers of the same era had vastly superior BASICs (such as Sinclair BASIC).
- chihuahua 4mo agoI agree, it seems very low-effort on Commodore's part to license this lowest-common-denominator BASIC with no support for graphics and sound other than POKE. Super lame, but they got away with it.
- jasonvorhe 4mo agoAmidst abysmal uptime, Ghostty leaving and now this, GitHub is accelerating their own downfall.
- JumpCrisscross 4mo agoHas Microsoft just created an editorial responsibility for itself to remove zero days from GitHub? If my software winds up with a zero day on GitHub, will Microsoft nuke that account, too?
- akerl_ 4mo agoWhy would taking this action have any implication for responsibility to take future actions against other accounts?
- JumpCrisscross 4mo agoLegally? I don’t know. More loosely, the fact that they deem this to be an appropriate action when it comes to their own interests would seem to condemn them if they refuse to take it when it comes to others’ interests, particularly those with whom it has a relationship of trust in any capacity.
- akerl_ 4mo agoOutside of legally, I’m not aware of any framework where “creates an editorial responsibly” makes sense. Even beyond that… most business relationships wouldn’t involve an expectation that Microsoft does things for other entities that it does for itself.
- JumpCrisscross 4mo agoI’m thinking of § 230 of the CDA [1], where the line between publisher/speaker and not can come down to editorial discretion. [1] https://en.wikipedia.org/wiki/Section_230 https://en.wikipedia.org/wiki/Section_230
- akerl_ 4mo agoIt can’t, and it doesn’t. Section 230 has no concern with publishers making editorial decisions. GitHub can moderate user content on its site however it wants.
- tptacek 4mo agoNo idea what's happening here, but the First Rule Of Major Bug Bounty Programs is that everybody involved on the vendor side is actively incentivized to pay out. In many cases, there are people whose internal metrics depend on payouts. Payouts are causes for celebration in these programs. Microsoft is almost certainly[†] not trying to save money by screwing over bounty claimants. This might not be true of small companies (and is a reason why small companies shouldn't run bug bounty programs), but it is definitely true of FAANG/MAG7-scale companies. This doesn't mean these bounty programs err on the side of paying out, or that they won't routinely make decisions that will piss you off. It does however work against claims that they're withholding payouts vindictively. [†] Only hedging because it's been a minute since I've talked to anyone at Microsoft.
- thaumasiotes 4mo agoTo corroborate, working in bug bounty triage, I never saw any evidence of reluctance to pay out.† The worst company-side behavior I observed was asking researchers to "please stay away from X" in their proof-of-concepts and then making higher payouts to researchers who ignored that instruction (because, after all, the demonstrated risk was higher!). On the other side of things, I saw one major program pay out at an inappropriately high tier, over and over again, because a long time ago the researcher had successfully argued that his garden-variety XSS exploit could be used to generate an effect that was listed at a higher payout rate, and then he made sure that whenever he found an XSS, he included a proof-of-concept generating that same effect. Other researchers reporting XSS got the listed XSS rate. † Actually, I can think of one time. Someone achieved the holy grail and installed a webshell on a company server, which under current guidelines would have been worth more than $10k. However, they didn't uninstall the webshell. They just filed their report and left it up. This enraged the head of the program, who commented specifically that he didn't want to pay out a bounty because of it. I don't recall whether a bounty was ultimately paid or not.
- arjvik 4mo agoooc, would you claim its the responsibility of the security researcher to remove the webshell, or the company's as soon as they were notified? was it publically discoverable and exploitable or was there some form of protection?
- mschuster91 4mo agoLol, they ban a security researcher from Github for embarassing them, but massgrave's Microsoft Activation Scripts isn't just still on Github but verified? Make it make sense, Microsoft.
- sgjohnson 4mo agoMicrosoft hasn’t particuarly cared about consumers pirating Windows for more than a decade. I’m pretty sure they make close to 0 money off Windows licensing to consumers.
- thewebguyd 4mo agoA quote from Billy G comes to mind > Although about 3 million computers get sold every year in China, people don't pay for the software. Someday they will, though," Gates told an audience at the University of Washington. "And as long as they're going to steal it, we want them to steal ours. They'll get sort of addicted, and then we'll somehow figure out how to collect sometime in the next decade. Microsoft's attitude has always been if someone is going to pirate an OS, they'd rather that be Windows than a competitor's platform.
- debugnik 4mo agoIs there any other OS that gets pirated these days? Are Hackintosh still a thing?
- mschuster91 4mo ago> Are Hackintosh still a thing? A dying breed, most Intel machines have already fallen out of support and the few remaining ones (e.g. 2019 16-inch MBP) won't get any new OS updates after end of this year.
- throwaway85825 4mo agoPirating windows keeps you in the ecosystem so they can sell ads/games/365/cloud etc.
- vasco 4mo agoThe NSA isn't even subtle anymore jeez.
- mmastrac 4mo ago_NSAKEY part deux
- rvz 4mo agoA perfect storm of GitHub's own self-destruction and downfall all done by themselves. Microsoft is playing with fire against a researcher that has a track record of finding 0 days out of thin air. Quite a dumb thing to do. This researcher should instead pivot to crypto smart contract bounties instead. A much larger payout there instead of compaines like Microsoft.
- Aurornis 4mo agoUser also got themselves banned from Gitlab, an unrelated company. Their quotes in the article are threatening violence and destruction toward Microsoft. I don’t know what’s going on, but given that they’re getting banned from multiple unrelated organizations and threatening to “crush their bones” and such, I suspect this is probably just a regular old case of someone being abusive and unhinged, getting banned because of it, and then claiming conspiracy. What, exactly, did this person post to GitHub and/or Gitlab that got them banned? We should all know by now that any exploits posted to GitHub are cloned and forked everywhere immediately. Why are these articles so vague about what was posted? Also, these conspiracy theories that the NSA or other .gov is forcing this are quite ridiculous, as it would be infinitely easier for them to just hand the guy a pile of money than to Streisand effect it with a visibly unhinged guy talking about dead man’s switches and crushing bones.
- ImPostingOnHN 4mo agoBefore we go down the road of analyzing someone's reaction, we should first analyze what they're reacting to: How much money did microsoft bilk this person out of? What is a reasonable reaction to someone taking that much money out of your paycheck?
- firefax 4mo agoAlso, as a practical matter, maybe do as someone says if they have this many zero days sitting around? While they may have violated various TOS, it's my understanding that dropping a zero day like one would drop the mic at the end of an epic rant is not inherently illegal. Maybe don't piss off your betters?
- bnagh 4mo agoLooks like Microslop will have a happy Bastille day. Getting popcorn.
- LelouBil 4mo agoVery important info: https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085 https://www.theregister.com/security/2026/05/28/microsoft-0-... In the linked Microsoft blog post, they say : > The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk. So are they lying ? Why would Nightmare-Eclipse not report them if they are not ? It's a very weird situation
- thewebguyd 4mo ago> the disclosures put our customers at unnecessary risk. That statement irks me. Responsible disclosure or not, It's Microsoft themselves that put their customers at risk, not the researcher.
- Cpoll 4mo agoThe industry, on average, approves of responsible disclosure because there's a tacit agreement that making risk-proof software isn't feasible. Though admittedly some companies don't seem to be trying very hard anymore. It's not a dichotomy either, they can both have put the customers at risk.
- ikidd 4mo agoEspecially since the only explanation for why this exists is as a backdoor.
- subscribed 4mo agoYeah, but the customer in this statement being entities that requested this backdoor. Not the people/companies who paid for the licences.
- firefax 4mo ago>Why would Nightmare-Eclipse not report them if they are not ? Maybe they're a foreign intelligence cutout masquerading as a burned researcher.
- ChrisArchitect 4mo agoRelated: Microsoft's stance on zero day exploits is a dumpster fire of their own making https://news.ycombinator.com/item?id=48313038 https://news.ycombinator.com/item?id=48313038
- rukshn 4mo agoI stopped reporting any security bugs I find in web apps because first time I did it I almost got arrested by the police. The second time I did it they contacted my employer directly without even getting back to me saying they were unhappy of me reporting it and wanted to write about it after they fixed the issue. Since then I decided it’s not worth all the hassle and I will let them be and I can also have a peaceful day.
- lionkor 4mo agoYou could try reporting them (the exploits) anonymously to a government agency
- ranger_danger 4mo agoSo they can exploit it in secret for their own benefit?
- lionkor 4mo agoIf you have so little trust in your government (maybe you're American?) it might be time for change!
- voakbasda 4mo agoNo shit. Mind telling us how? Because elections sure aren’t going to do it. edit: sorry, there is so much of this sentiment, and the system is proven to be rigged. We know that things have gotten bad. Really bad. And there’s little hope of it self-correcting. The corruption is too deep and now seems unabashed. I seriously do want advice on how to change things, but three out of the four boxes meant to preserve liberty have proven to be inadequate. I see no future that doesn’t involve violent upheaval. Convince me otherwise.
- lionkor 4mo agoI agree with the violent upheaval idea. I believe that all systems which promote and enforce radical patriotism "no matter what" are bound to end up there. It's also getting more and more difficult for your country to keep allies, what with bombing and assaulting every single possible place for maximum profit extraction. Lots of people in the world have a hatred for the USA (as an entity) that is only paralleled by e.g. Nazi Germany. The only way to make a change is to get up and make a change, and if you can't because you're that deep in the hole, as you said, violent upheaval. I really wish that the USA would just wake up one morning and decide to make a change, without violence and bloodshed, to look at other Western countries for inspiration and create a more human society.
- karel-3d 4mo agowhy doesn't he sell those to someone like zerodium the bugs he is publishing are exactly the class of bugs that they would love to buy
- breppp 4mo agoThe combination of an overly unstable dramatic researcher, a tech news community which will undermine truth in a desperate plead for some clicks and people that are readily willing to believe everyone is constantly just casually in contact with the NSA, gives us these third rate stories
- b3lvedere 4mo agoIn the past recent months i've been dealing with a lot of strange digital responses at various related things. It caused a lot of frustration and i couldn't exactly pinpoint what i was doing wrong. Then i read this sentence in the article: "But to save money, Microsoft fired the skilled people, leaving flowchart followers." Flowchart followers.. Now those are nice words to remember. It says it all. Not paid to think, but to follow pre-paved processes. My guess is that in the near future one will have to deal with a lot more flowchart followers, wether they be digital or actual human beings.
- throwburn202605 4mo agoA lot of blue collar trades - mechanic/electrician/builder etc following the `flowchart` is the `law` of the land and process is written in blood and liability Whereas IT/Ops/developers see themselves as artisinal, free thinking, intellectual beings. Where skill is related to shortcuts, hacks, and thinking outside the box compared to following process
- radishingr 4mo agoIt depends, flowcharts are great for defined processes, but troubleshooting (which vulnerability research mirrors) is not a flowchart or checklist or task list.
- pjc50 4mo agoAnd in other blue collar union environments, following the book is known as "work to rule" and considered a mild form of sabotage/industrial action.
- b3lvedere 4mo agoI am all in favor for extensive logging, documentation and following the processes, especially regarding safety. But there will always be miscommunication and cases where some thinking or adaptation of those processes are required. Stopping that for cost reduction will eventually lead to enshittification.
- 1718627440 4mo ago
- stevefan1999 4mo agoI mean he should sell those 0days to exploit.im market for a good money instead of going for "whitehat" if you want maximum damage
- frobisher 4mo agoWe need to move to IPFS or something federated for source code
- PunchyHamster 4mo agoHosting it yourself is trivial and cheap. Git is not heavy protocol, nor git over https
- sspoisk 4mo agoThis situation highlights the inherent conflict of interest in Microsoft owning GitHub. While GitHub has clear terms of service regarding the hosting of active, weaponized exploits, the optics of banning a researcher who specifically targeted Windows are always going to look vindictive, regardless of the justification.
- StatelessAnton 4mo agoOne should just exploit it next time :D
- sscaryterry 4mo agoJust create a new account :D
- ptrl600 4mo agoLots of copies of the Windows source code still on GitHub, which is problematic if you're interested in NT and want to contribute to Wine or something...hard to avoid running into restricted code
- panny 4mo agoMicrosoft owns Github and Windows, makes sense. "Security researchers" love attention however, and I'm going to guess this one knew it would happen and is now making hay on the fact that it did. Now let me roll out the tired authoritarian excuses to wrap up the thread. >It's a private company. They can do what they want. >Freedom of speech isn't freedom from consequences. >Build your own github. Did I miss any?
- onesingleblast 4mo agoYeah because he didn't responsibly report it. What did he expect?
- Szpadel 4mo agonow, that should teach him to sell those on black marked instead I'm mostly joking here, but Microsoft is one of few companies that handle cyber security in a way that really incentive people to not report them. it's either by downplaying impact and not paying or paying very little or doing other researcher hostile activities. especially that someone here mentioned some time ago that black market pays about 3x for the same class of vulnerability, so you need fairly high moral standards to go direct way
- qsxfthnkp2322 4mo agoAnd now we know a large reason why Microsoft purchased GitHub.
- packspro 4mo ago[flagged]