Live data from Hacker News

GitHub bans security researcher who posted zero-day Windows exploits

tomshardware.com

81–90 of 274 posts

Re: GitHub bans security researcher who posted zero-day Windows exploits

#81
Very important info: https://www.theregister.com/security/2026/05/28/microsoft-0-...

In the linked Microsoft blog post, they say :

> The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk.

So are they lying ? Why would Nightmare-Eclipse not report them if they are not ?

It's a very weird situation

Re: GitHub bans security researcher who posted zero-day Windows exploits

#82

Earlier quoted context omitted.

This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.

SandboxEscaper is still alive, but yeah, Eclipse's prolific vuln dropping reminds me of her.

[dead]

Re: GitHub bans security researcher who posted zero-day Windows exploits

#83
post #37
post #28

Earlier quoted context omitted.

> They seem to have a personal vendetta against Microsoft Probably because they were forced to use MS-DOS when so many better options were killed off by Microsoft's monopolistic and anti-consumer underhanded business tactics... I might be projecting.

I was forced to use ms basic on my c64. Never forgive, never forget.

I always found it weird to ship a BASIC interpreter that didn't have specialised commands (unless you count POKE) to access the graphics and sound capabilities of a computer like the C64. Some computers of the same era had vastly superior BASICs (such as Sinclair BASIC).

Re: GitHub bans security researcher who posted zero-day Windows exploits

#84

Has Microsoft just created an editorial responsibility for itself to remove zero days from GitHub? If my software winds up with a zero day on GitHub, will Microsoft nuke that account, too?

Why would taking this action have any implication for responsibility to take future actions against other accounts?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#86

User also got themselves banned from Gitlab, an unrelated company. Their quotes in the article are threatening violence and destruction toward Microsoft. I don’t know what’s going on, but given that they’re getting banned from multiple unrelated organizations and threatening to “crush their bones” and such, I suspect this is probably just a regular old case of someone being abusive and unhinged, getting banned becaus…

Before we go down the road of analyzing someone's reaction, we should first analyze what they're reacting to: How much money did microsoft bilk this person out of? What is a reasonable reaction to someone taking that much money out of your paycheck?

Re: GitHub bans security researcher who posted zero-day Windows exploits

#87

Earlier quoted context omitted.

But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title. He also got banned from Gitlab, which isn’t related to Microsoft at all.

Ever considered these aren't the full set of exploits the researcher discovered? Or that he can find more since he found these? If I found a bunch, I'd certainly withhold a few as insurance.

He's claimed that he has more as well. He seems to have a personal vendetta against Microsoft going by his blog, said nothing will be released in June but will in July: https://deadeclipse666.blogspot.com/2026/05/july-14th.html

Re: GitHub bans security researcher who posted zero-day Windows exploits

#88

Lol, they ban a security researcher from Github for embarassing them, but massgrave's Microsoft Activation Scripts isn't just still on Github but verified ? Make it make sense, Microsoft.

Microsoft hasn’t particuarly cared about consumers pirating Windows for more than a decade. I’m pretty sure they make close to 0 money off Windows licensing to consumers.

A quote from Billy G comes to mind

> Although about 3 million computers get sold every year in China, people don't pay for the software. Someday they will, though," Gates told an audience at the University of Washington. "And as long as they're going to steal it, we want them to steal ours. They'll get sort of addicted, and then we'll somehow figure out how to collect sometime in the next decade.

Microsoft's attitude has always been if someone is going to pirate an OS, they'd rather that be Windows than a competitor's platform.

Re: GitHub bans security researcher who posted zero-day Windows exploits

#89

Researcher seems a bit unhinged.

This often seems to be the case for the most expert researchers, all a bit quirky. Anyone remember SandboxEscaper? I think they are deceased now but they were dropping Windows 0 days left and right. That person was quite a character. It's hard to describe it without potentially incurring the wrath of someone here but those who know, know.

This the same person? https://www.patreon.com/SandboxEscaper

Re: GitHub bans security researcher who posted zero-day Windows exploits

#90
post #84

Has Microsoft just created an editorial responsibility for itself to remove zero days from GitHub? If my software winds up with a zero day on GitHub, will Microsoft nuke that account, too?

Why would taking this action have any implication for responsibility to take future actions against other accounts?

Legally? I don’t know.

More loosely, the fact that they deem this to be an appropriate action when it comes to their own interests would seem to condemn them if they refuse to take it when it comes to others’ interests, particularly those with whom it has a relationship of trust in any capacity.

Post reply on HN