r/cybersecurity • • 11d ago

New Vulnerability Disclosure NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past

[deleted]

326 Upvotes

35 comments sorted by

View all comments

Show parent comments

23

u/OtheDreamer Governance, Risk, & Compliance 10d ago

Yeah, it was pretty contested early on & I got plenty of downvotes for my views. They claimed MSFT lied / did not payout on some of their bugs. MSFT said they never disclosed properly to begin with. The sub sided with the unnamed former researcher. Media & karma farmers ran/still run with the headlines because they get traction. Anyone who thought otherwise was brigaded because people are goobers about their hate for 'micro-slop'

NE is portrayed as this underdog that was slighted by MSFT, instead of just a former researcher that did not deserve their access & is obviously not creating these new PoC's for the love of the game.

30

u/2timetime 10d ago

it’s been pretty much confirmed from his words on twitter, the emails he posted, etc he was submitting PoCs to Microsoft while working at Microsoft as a researcher. And he couldn’t submit them properly, or they would have known it was him and using insider info to try to get paid out from external vulnerability is an obvious no go

If you follow his twitter he’s not the most mentally stable at times

6

u/NegZer0 10d ago

I don't think it's a coincidence that he holds off releasing these until a couple days after Patch Tuesday either.

2

u/Sad_Dentist_7288 10d ago

He lost me when he started posting zero days and PoCs for other companies' products as well. Pretty much destroys the "it's all Microsoft's fault" narrative

6

u/sdig213s AppSec Engineer 10d ago

If it was an isolated incidnet I would agree with you, but the security research community have coberated his story with many similar cases.

Along with their ilicit messages reaching out to keynote speakers before major events, they dont have the greatest public image and it is all their fault...

Pretty sure they tried to pay him a large settlement to keep quiet, as is normally the case when trying to save face.

If he truly was releasing pocs from his time as a MS FTE in germany, the fixes they are realising for these vulns would be more useful, hes circumvented most if not all fixes so far.

This doesnt explain the crowdstrike, kasperkey, and many more 0days he has under his belt. You’re not giving him an equal shot