<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual]]></title><description><![CDATA[<p>Microsoft, who banned Nightmare-Eclipse from their GitHub platform, <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure" rel="nofollow noopener">conveys their displeasure with said individual</a></p><p>Also manages to sprinkle in a few references to not using CVD as being not "responsible".  (Microsoft was a big proponent of the term "responsible disclosure", which has gone by the wayside because it tends to favor vendor-centric perspective in a subjective and moralizing way.)</p>]]></description><link>https://board.circlewithadot.net/topic/cb477817-ad91-4507-a7e3-3cf2f58e86ce/microsoft-who-banned-nightmare-eclipse-from-their-github-platform-conveys-their-displeasure-with-said-individual</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 17:39:11 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/cb477817-ad91-4507-a7e3-3cf2f58e86ce.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 27 May 2026 23:09:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 14:02:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> </p><blockquote><p>Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable...</p></blockquote><p>Assertion not supported by currently available data. There are plenty of historical examples of vendors which have refused to act on vulnerabilities which impact customers until their arms are twisted via public disclosure.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/TomSellers/statuses/116652568360789088</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/TomSellers/statuses/116652568360789088</guid><dc:creator><![CDATA[tomsellers@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 14:02:14 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 12:06:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/chthonic%40infosec.exchange">@<span>chthonic</span></a></span> </p><blockquote><p>Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity – coordinating as needed with law enforcement around the world. </p></blockquote><p>This is not an olive branch. It's a threat.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116652115208490408</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116652115208490408</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 12:06:59 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 10:31:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/snowride509%40infosec.exchange" rel="nofollow noopener">@<span>snowride509</span></a></span> <span><a href="/user/chthonic%40infosec.exchange" rel="nofollow noopener">@<span>chthonic</span></a></span> <span><a href="/user/wdormann%40infosec.exchange" rel="nofollow noopener">@<span>wdormann</span></a></span> Guidelines mudlines. It's not about that.</p><p>Researchers don't have to participate in responsible disclosure. They're not contractually obligated, unless they participate in bug bounties. They can just release their findings whenever they want to.</p><p>The only thing stopping most researchers from doing it is a social contract whereby the vendor takes them seriously, fixes the bug in a timely manner, and gives them credit. This has been the model the security industry coalesced around for a while.</p><p>Microsoft blatantly broke that social contract, and now they suffer the consequences, and cry crocodile tears about it. You asked for it, Microsoft. FAFO, as the kids these days say.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.tech.lgbt/media_attachments/files/116/651/720/244/998/101/original/be8a1f26b56e034e.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.tech.lgbt/media_attachments/files/116/651/722/298/421/591/original/1cf71131e4bd4ffb.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/users/pq1r/statuses/116651738404099182</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/users/pq1r/statuses/116651738404099182</guid><dc:creator><![CDATA[pq1r@tech.lgbt]]></dc:creator><pubDate>Thu, 28 May 2026 10:31:10 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 05:31:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/tiraniddo%40infosec.exchange">@<span>tiraniddo</span></a></span> <span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> more emphasis on "responsibility" here</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://blogs.microsoft.com/on-the-issues/2026/05/01/from-capability-to-responsibility-securing-our-global-digital-ecosystem-with-next-generation-ai/" title="From Capability to Responsibility: Securing our global digital ecosystem with next‑generation AI">
<img src="https://blogs.microsoft.com/wp-content/uploads/sites/5/2026/04/FY26_OML-Q4–PA-Cybersecurity-Mythos-Blog-Copyreview_05-1024x576.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://blogs.microsoft.com/on-the-issues/2026/05/01/from-capability-to-responsibility-securing-our-global-digital-ecosystem-with-next-generation-ai/">
From Capability to Responsibility: Securing our global digital ecosystem with next‑generation AI
</a>
</h5>
<p class="card-text line-clamp-3">Cybersecurity is at a turning point as AI accelerates vulnerability discovery, requiring safeguards and faster response.</p>
</div>
<a href="https://blogs.microsoft.com/on-the-issues/2026/05/01/from-capability-to-responsibility-securing-our-global-digital-ecosystem-with-next-generation-ai/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://blogs.microsoft.com/wp-content/uploads/sites/5/2017/08/favicon-599dd744b8cac.jpg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />







<p class="d-inline-block text-truncate mb-0">Microsoft On the Issues <span class="text-secondary">(blogs.microsoft.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/aristot73/statuses/116650558446737781</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/aristot73/statuses/116650558446737781</guid><dc:creator><![CDATA[aristot73@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 05:31:05 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 05:00:12 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> "gone by the wayside" good, they literally made it up to bully researchers.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/0x00string/statuses/116650437039385754</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/0x00string/statuses/116650437039385754</guid><dc:creator><![CDATA[0x00string@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 05:00:12 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 04:55:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> and zero acknowledgement that MiniPlasma shouldn't even exist in any form. Total lack of self awareness.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/tiraniddo/statuses/116650417188421924</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/tiraniddo/statuses/116650417188421924</guid><dc:creator><![CDATA[tiraniddo@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 04:55:09 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 01:03:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> we should rename “responsible disclosure” to “Samaritan snare”</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116649507615893035</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116649507615893035</guid><dc:creator><![CDATA[joshbressers@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 01:03:50 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 00:59:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/chthonic%40infosec.exchange">@<span>chthonic</span></a></span> <span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> This is absolutely not “normal” but it does happen enough for the pattern to show itself…namely the vendor here is making ticky-tack calls to not provide a bounty.  Yes,  MSRC has public guidelines, but they are often too rigid, IMHO.  Whatever bounties were in play, they are cheaper than all the ish that has happened, namely the brand impact to MSFT.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/snowride509/statuses/116649490852216641</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/snowride509/statuses/116649490852216641</guid><dc:creator><![CDATA[snowride509@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 00:59:35 GMT</pubDate></item><item><title><![CDATA[Reply to Microsoft, who banned Nightmare-Eclipse from their GitHub platform, conveys their displeasure with said individual on Thu, 28 May 2026 00:03:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> It seems like Microsoft is also extending an olive-branch towards the end where they state they will work with any disclosure reported by whoever, regardless of reputation. From what I gather here it looks like they're laying the DCU threat while trying to keep a door open for negotiation with Nightmare-Eclipse. As a newbie, this is not how it usually goes correct? And there's no way for the public as third parties to verify either sides claims (did Nightmare-Eclipse report and then an agreement was not verified or did they simply not report at all?)</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116648919470972362/statuses/116649270315923854</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116648919470972362/statuses/116649270315923854</guid><dc:creator><![CDATA[chthonic@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 00:03:30 GMT</pubDate></item></channel></rss>