Microsoft Criticises Public Zero-Day Disclosures After GitHub Account Removal

Software giant reinforces coordinated disclosure policy following researcher’s public vulnerability releases.

Illustration: Microsoft Criticises Public Zero-Day Disclosures After GitHub Account Removal

Software giant reinforces coordinated disclosure policy following researcher’s public vulnerability releases.

  • Microsoft publicly defended coordinated vulnerability disclosure practices
  • Researcher Chaotic Eclipse disclosed multiple zero-day vulnerabilities publicly
  • GitHub removed the researcher’s account amid the disclosure controversy

Microsoft has publicly reinforced its support for coordinated vulnerability disclosure (CVD) following controversy over a security researcher’s public release of multiple zero-day vulnerabilities.

The researcher, known as Chaotic Eclipse or Nightmare-Eclipse, disclosed details of several zero-day vulnerabilities without providing advance notice to affected vendors. The Hacker News reported that GitHub subsequently removed the researcher’s account.

Microsoft’s statement emphasised the importance of responsible disclosure practices, urging researchers to share vulnerability findings privately with vendors before public release. The company argued this approach allows vendors to properly assess impact and develop fixes before vulnerabilities become publicly known.

The coordinated disclosure model typically involves researchers notifying vendors of security flaws privately, allowing time for patches to be developed and deployed before public disclosure. This contrasts with immediate public disclosure, which can leave systems vulnerable while fixes are being developed.

The incident highlights ongoing tensions in the security research community about disclosure timing and practices. While some researchers advocate for immediate public disclosure to pressure vendors into faster responses, others support coordinated approaches that balance transparency with security.

GitHub’s decision to remove the researcher’s account suggests the platform may be taking a more active role in moderating vulnerability disclosures hosted on its service.

Why It Matters

CISOs should understand this controversy reflects broader industry tensions over vulnerability disclosure timelines that directly impact defensive strategies. Microsoft’s public stance reinforces expectations that security teams will have advance notice to prepare patches and defensive measures before vulnerabilities become public knowledge.

The GitHub account removal also signals that major platforms may increasingly moderate security research content, potentially affecting where and how vulnerability information reaches security teams.

What To Do Now

  • Review your organisation’s vulnerability disclosure policy and ensure it clearly defines expectations for researchers reporting security flaws
  • Monitor official vendor security channels rather than relying solely on public disclosure platforms for vulnerability intelligence
  • Establish relationships with security research communities that follow coordinated disclosure practices

Sources