Microsoft and Researcher Nightmare Eclipse Trade Public Accusations Over Disclosure Gone Wrong
A researcher who published unpatched vulnerability details says Microsoft deleted his accounts and ruined his life. Microsoft says his drops put proof-of-concept code in criminals' hands. Neither is entirely wrong.

The researcher known as Nightmare Eclipse has disclosed bugs before patches existed. That much is not in dispute. What is disputed — loudly, across public posts — is who bears responsibility for the breakdown that preceded those disclosures.
Eclipse claims Microsoft refused to communicate with him, deleted the account he used to submit bugs, and then publicly defamed him via its advisory for CVE-2026-45585. "You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so," he wrote. He also alleged Microsoft told him personally it would "ruin my life" and that the company "sabotage[s] people a lot." His posts escalated. One referenced July 14th and bones being shattered — a turn of phrase that moved this well past a policy disagreement.
Microsoft's public response leaned institutional. The company acknowledged the disclosures, called them uncoordinated, and noted that "proof-of-concept code for unpatched vulnerabilities" handed to bad actors carries "real-world consequences." It also managed a dig at Eclipse's reputation while ostensibly welcoming all researchers: "We always have and will continue to welcome vulnerability submissions from anyone through our public researcher portal, regardless of past interactions or reputation."
Tom Gallagher, VP of engineering at the Microsoft Security Response Center, offered something closer to reflection. He wrote that severity assessments remain grounded in real-world impact and exploitability, but suggested the pace of applying disclosure fundamentals may need to change. He stopped short of announcing any policy revision.
Industry observers split the blame evenly. Brian Levine of FormerGov put it plainly: Microsoft is right that uncoordinated zero-day drops create immediate customer risk, and researchers are right that vendors sometimes move only when pushed. Gary Longsine, CEO of Intrinsic Security, was less generous toward Eclipse. "Legitimate security researchers don't do things this way," he said, calling the researcher an adversary rather than a peer.
The structural tension here is familiar. Vendors cannot patch everything at once. Researchers, unpaid and often ignored, watch months pass while a flaw sits open. Microsoft's own history includes an eight-year delay patching a known Microsoft Authenticator vulnerability — fixed only after public exposure forced the issue.
Ishraq Khan, CEO of Kodezi, flagged what he sees as the deeper damage. AI-assisted vulnerability discovery is accelerating the pace at which flaws are found and, crucially, exploited. The window vendors once had — measured in months — now compresses to hours. A trust breakdown that once affected a handful of people can now cascade across entire ecosystems. "Responsible disclosure only works when both sides believe the system is functioning," Khan said. Once that faith fractures, the model breaks for everyone.
What Eclipse will or will not release on July 14th remains unclear. Microsoft declined to comment further.



