The stories buried, spiked, or spun.
Global Power

GitHub bans security researcher who posted zero-day Windows exploits

Share
GitHub bans security researcher who posted zero-day Windows exploits

What they're not telling you: Microsoft's GitHub Purge: Who Pays When Bug Bounties Become a Hostage Negotiation Microsoft deleted a researcher's account after he refused to stay silent about unpaid zero-day bounties, then banned him from GitHub when he went public—a move that reveals how market-dominant platforms weaponize their control of infrastructure against the security researchers who sustain their products. The researcher known as Nightmare-Eclipse, operating under the handle Chaotic Eclipse, reported six zero-day vulnerabilities to Microsoft's Security Response Center (MSRC) beginning in April. According to Eclipse's own accounting, Microsoft either ignored these reports or refused to pay bounties totaling what Eclipse claims amounts to significant financial harm.

What the Documents Show

In response, Eclipse published BlueHammer, an unpatched zero-day exploit, without prior warning. Microsoft's reply was algorithmic: the company deleted Eclipse's Microsoft research account, then escalated by banning his GitHub account entirely—the primary distribution point for security research in the developer economy. Here's what matters: the MSRC bug bounty program offers up to $30,000 to $100,000 per endpoint zero-day, scaling to $250,000 for Hyper-V vulnerabilities. These are not academic figures. They represent Microsoft's declared valuation of the work required to find critical security flaws before hostile actors do.

🔎 Mainstream angle
The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.

Follow the Money

Yet the mechanics of that bounty program remain opaque. Microsoft decides unilaterally whether a report qualifies, whether payment is warranted, and how long researchers wait for answers. There is no appeals process with independent arbitration. There is no regulatory oversight. There is no published timeline of payment disputes. Eclipse's language in public statements is raw and suggests genuine financial desperation.

What Else We Know

He claims Microsoft told him personally "they will ruin my life and they did." He references a dead-man switch—implying additional exploits are staged for automatic release. He states directly: "I got zero pennies from doing so." Whether Eclipse's account of events is complete or emotionally heightened, the underlying structure is clear: a researcher discovered critical security gaps in products used by millions of enterprises and government agencies, reported them through the official channel, received either silence or rejection, and then faced account deletion and platform banning when he went public. The GitHub ban is the telling detail. GitHub, owned by Microsoft since 2018, hosts the infrastructure through which the global security research community coordinates vulnerability disclosure, peer review, and remediation. By deploying that ownership stake as a weapon against a researcher disputing payment terms, Microsoft converted a key piece of the internet's security backbone into a leverage point in a commercial dispute. The researcher moves to GitLab.

Diana Reeves
The Diana Reeves Take
Corporate Watchdog & Money & Markets

Microsoft is operating a private court system to adjudicate its own payment obligations, and when the accused researcher refuses the verdict, Microsoft evicts him from the courthouse. That's the pattern here, and it extends far beyond one company.

What I find striking is how completely the security research community has outsourced its existence to platforms controlled by the companies being researched. GitHub hosts the code. Twitter amplifies the findings. Azure runs the infrastructure. When a researcher disputes payment from Microsoft, Microsoft controls every channel through which that dispute can be aired or resolved. The company holds the bounty budget, the platform, the deletion authority, and the market power to make the researcher's work disappear.

The official story—that GitHub enforces community standards and Microsoft protects its IP—obscures who actually benefits: Microsoft avoids paying disputed bounties while retaining the option to ban researchers who cost the company money through reputational damage. Eclipse absorbs the loss and the deplatforming. End users and enterprises never learn whether the vulnerabilities that remain unpatched pose active risk to their systems.

Watch for whether any researcher subject to account deletion or bounty rejection files a formal complaint with state attorneys general. That pressure, and only that pressure, might produce the first transparent accounting of how Microsoft's MSRC actually operates.

Primary Sources

What are they not saying?
Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.

Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.

Share
Part of our Global Power coverage
See the full picture on our Global Power hub — including our ongoing coverage of sanctions, alliances, and geopolitical realignment.
How We Report Global Power

This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (an official government or diplomatic statement, wire-service reporting (Reuters, AP, AFP) we cite by name, or a named think-tank/NGO report) and reports what that source states, attributed to it — it reports what that source states and does not predict how a conflict or negotiation resolves. Part of our Global Power hub. Found an error? Tell us.