I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.
But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.
GitHub bans security researcher who posted zero-day Windows exploits
71–80 of 274 posts
Re: GitHub bans security researcher who posted zero-day Windows exploits
#72Also recently: Satya Nadella says as much as 30% of Microslop code is written by AI: https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-a...
Re: GitHub bans security researcher who posted zero-day Windows exploits
#73Re: GitHub bans security researcher who posted zero-day Windows exploits
#74Researcher seems a bit unhinged.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#75Re: GitHub bans security researcher who posted zero-day Windows exploits
#76I can’t help but feel Microsoft will regret this. Guy finds zero days and gets no compensation. Instead gets banned. Guy sells zero days elsewhere.
But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#77What's the backstory on this researcher? They seem to have a personal vendetta against Microsoft and thus releasing zero days that he found with the help of AI? Seems like the gold rush period is over for bounty hunters and its more about who has access to hardware/token capital.
It sounds like they're pissed because they produced a large number of high-value exploits, sent them to MS, were treated like crap, and then MS refused to honor their own published bounties: > But to save money, Microsoft fired the skilled people, leaving flowchart followers. I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MS…
How do we know they didn't? It's called zero-day because Microsoft wasn't aware of the exploits until today. It doesn't mean that no other parties have known about them.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#78Earlier quoted context omitted.
Do we have any evidence they did that other than the comment you replied to speculating?
Yes they definitely did that. Find evidence to the contrary.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#79> forcing them to pack up and move shop to GitLab instead. https://gitlab.com/nightmare-eclipse Blocked user @nightmare-eclipse Looks like they’re banned on GitLab as as well?
Are there any copies of what he supposedly posted? I have a hard time believing someone posted groundbreaking exploits to two separate Git websites and not a single person cloned them. I also think it’s funny that people are alleging .gov conspiracies that end in a publicly hosted “blocked user” page instead of just 404-ing or something.
https://github.com/xiaoji235/bitlocker-bypass-tool-for-winre
Unfortunately I don't think there is any way to see a list of all the forks now that the main repo is dead, but you can search the phrase "A huge thanks to MORSE, MSTIC and Microsoft GHOST for making this public disclosure possible" to find more copies.
Re: GitHub bans security researcher who posted zero-day Windows exploits
#80Earlier quoted context omitted.
It sounds like they're pissed because they produced a large number of high-value exploits, sent them to MS, were treated like crap, and then MS refused to honor their own published bounties: > But to save money, Microsoft fired the skilled people, leaving flowchart followers. I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MS…
> and the response was flow chart tech support with a "buy a webcam" cherry on top I feel safe in saying that they don't want a video of you at your keyboard typing stuff. An exploit video is a recording of your screen, not of you.
Doesn't sound like it for these exploits specifically (except Yellow Key), but I could be wrong, and again: that's just for these exploits specifically