LIVE NEWS
  • Italy seizes gold, luxury villas and cash tied to Sicilian Mafia drug-trafficking
  • Dogecoin Slips Below 10 Cents With More Downside Ahead
  • Microsoft Condemns “Uncoordinated” Zero Day Disclosures
  • A new report shows how close American households are to the financial edge : NPR
  • Six in 10 Neets have never had a job, says Alan Milburn, as he warns of ‘generational faultline’ – UK politics live | Politics
  • Goldman Sachs Just Did a Huge Shake Up of Its Crypto Portfolio. Here’s What It Means.
  • Xi’s summit diplomacy reveals an increasingly confident China
  • Millions of planets might form around supermassive black holes
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Microsoft Condemns “Uncoordinated” Zero Day Disclosures
Cybersecurity

Microsoft Condemns “Uncoordinated” Zero Day Disclosures

primereportsBy primereportsMay 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Microsoft Condemns “Uncoordinated” Zero Day Disclosures
Share
Facebook Twitter LinkedIn Pinterest Email


In a new bulletin, Microsoft has criticized security researchers for publicly reporting vulnerabilities in the company’s products before patches were available and without prior notice.

These “uncoordinated disclosures put our customers at unnecessary risk,” the tech giant said.

Six Microsoft Zero Days Disclosed Before Patches

The statement, published on May 27, mentioned six vulnerabilities that “were not responsibly disclosed.” These are:

  • ‘Red Sun’ (CVE-2026-41091): a privilege escalation vulnerability in Microsoft Defender (CVSS: 7.8)
  • ‘BlueHammer’ (CVE-2026-45498): another privilege escalation vulnerability in Microsoft Defender (CVSS: 7.8)
  • ‘YellowKey’ (CVE-2026-45585): a security feature bypass vulnerability in Windows BitLocker (CVSS: 6.8)
  • ‘Undefend’ (CVE-2026-45498): a denial-of-service vulnerability in Microsoft Defender (CVSS: 4.0)
  • ‘GreenPlasma,’ a privilege escalation vulnerability in Windows BitLocker
  • ‘MiniPlasma,’ a privilege escalation vulnerability in the Windows Cloud Filter driver

Because of these uncoordinated disclosures, Microsoft security teams “have been working around the clock” to investigate these vulnerabilities and develop mitigation measures and work on security patches.

Meanwhile, the rogue disclosures allowed to “put proof-of-concept [exploit] code for unpatched vulnerabilities into the hands of bad actors,” which Microsoft said is “never justifiable.”

“We remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem,” the company said.

Microsoft Urges Responsible Disclosures

The company encouraged security researchers to follow industry standard coordinated vulnerability disclosure (CVD) procedures, where a vulnerability finder and the owner of the vulnerable products convene an embargo period – typically 90 days – to allow the latter to develop patches before the vulnerability is made public.

In exchange, the researcher typically gets credited for finding the vulnerability and is compensated for their contribution.

Read more: How to Disclose, Report and Patch a Software Vulnerability

CVD processes have typically been adopted through bug bounty programs, crowd-sourced bug hunting platforms and spontaneous vulnerability reporting activities.

“Every year, we work with hundreds of security researchers through CVD,” noted Microsoft.

“This partnership allows us to make updates to impacted services before proof-of-concept code can make it into the hands of bad actors. Through this valuable partnership we also ensure researchers are compensated for their responsible disclosures and publicly acknowledged for their expertise,” the company added.

“We realize that we will not always agree on everything, but we are committed to transparency and continue to create opportunities for dialogue.”

AI Boom Puts 90-Day Disclosure Rule Under Pressure

Recently, however, prominent voices in the cybersecurity industry have started to warn that the traditional CVD model must be reimagined, with some declaring that the standard 90-day embargo is effectively dead.

Experts argue that these disclosure windows must drastically shrink to adapt to the massive acceleration of vulnerability research driven by advanced AI tools like Anthropic’s Claude Mythos and OpenAI’s GPT5.5-Cyber.

Read now: What Fronter AI Models Like Mythos and GPT-Cyber Mean for Modern Cybersecurity

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleA new report shows how close American households are to the financial edge : NPR
Next Article Dogecoin Slips Below 10 Cents With More Downside Ahead
primereports
  • Website

Related Posts

Cybersecurity

Whoop vs. Fitbit Air: I’ve tested both trackers for health and fitness, and this model wins

May 27, 2026
Cybersecurity

Can you enforce strong Active Directory password rules without frustrating users?

May 27, 2026
Cybersecurity

State Cyber Leaders Beg Congress for More Funding, Support

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

Together AI Open-Sources OSCAR: An Attention-Aware 2-Bit KV Cache Quantization System for Long-Context LLM Serving

May 26, 20267 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20265 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Italy seizes gold, luxury villas and cash tied to Sicilian Mafia drug-trafficking
  • Dogecoin Slips Below 10 Cents With More Downside Ahead
  • Microsoft Condemns “Uncoordinated” Zero Day Disclosures
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.