Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    Massive Pentagon Data Breach Exposes Records of Over 3 Million People

    October 8, 2026

    Why Amazon Wants Investors Buying $8 Billion of Its Nvidia Chips

    October 8, 2026

    Salesforce Agentforce Flaws Allowed Hackers to Steal Data Without a Click

    October 8, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      Massive Pentagon Data Breach Exposes Records of Over 3 Million People

      October 8, 2026

      Why Amazon Wants Investors Buying $8 Billion of Its Nvidia Chips

      October 8, 2026

      Google Reveals AI Is Discovering Increasingly Dangerous Software Vulnerabilities

      October 7, 2026

      Nscale Files IPO to Test Investor Appetite for AI Cloud Infrastructure

      October 7, 2026

      Google Home Now Supports ChatGPT and Claude via New MCP Server

      October 6, 2026
    • Crypto

      A Firmware Flaw in One of the Most Trusted Bitcoin Hardware Wallets Just Drained Over $70 Million in Crypto. The Coldcard Breach Is a Reminder That Cold Storage Is Only as Safe as the Code Running Inside It

      August 29, 2026

      Market Collapse: What Happened to NFTs?

      April 23, 2026

      Quantum Computing Advances Force Coinbase and Institutional Custodians to Rethink Crypto Security

      March 8, 2026

      AI Assisted Hacking Groups Target Crypto Firms With Multi-Layered Social Engineering

      February 18, 2026

      Global Crypto Regulations Expand as 2026 Begins With New Data Collection Frameworks and National Laws

      January 16, 2026
    • Gadgets & Smart Tech
      Featured

      Google Home Now Supports ChatGPT and Claude via New MCP Server

      By fariehanOctober 6, 2026
      Recent

      Google Home Now Supports ChatGPT and Claude via New MCP Server

      October 6, 2026

      Waymo Plans Fully Driverless Taxis on Tokyo Streets Without Safety Drivers

      September 28, 2026

      Tesla Cybercab Faces NHTSA Probe After Austin Launch

      September 19, 2026
    • Cybersecurity & Online Safety

      Massive Pentagon Data Breach Exposes Records of Over 3 Million People

      October 8, 2026

      Salesforce Agentforce Flaws Allowed Hackers to Steal Data Without a Click

      October 8, 2026

      Google Reveals AI Is Discovering Increasingly Dangerous Software Vulnerabilities

      October 7, 2026

      Nvidia Builds New Security System to Stop Rogue AI Agents

      October 5, 2026

      Why Google Refuses to Give Everyone Access to Gemini 4 Argon

      October 5, 2026
    PhronewsPhronews
    Home»Cybersecurity & Online Safety»A Researcher Microsoft Banned from GitHub Just Dropped a Zero-Day on Patch Tuesday for the Third Month Running. The Company Has No Real Way to Stop Them.
    Cybersecurity & Online Safety

    A Researcher Microsoft Banned from GitHub Just Dropped a Zero-Day on Patch Tuesday for the Third Month Running. The Company Has No Real Way to Stop Them.

    preciousBy preciousJune 21, 2026No Comments
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Photo Credit: Costfoto/NurPhoto via Getty Images

    Microsoft confirmed its June 2026 Patch Tuesday update on June 9, fixing dozens of Windows vulnerabilities. Hours later, a researcher already banned from GitHub published a new zero-day exploit targeting Microsoft Defender, marking the third consecutive month the researcher has timed a disclosure to Patch Tuesday, which is the day Microsoft ships its monthly batch of security fixes.

    What Happened

    On June 9, the researcher known as Nightmare Eclipse, who also posts as Chaotic Eclipse, published proof of concept code for a new Windows zero day named RoguePlanet. The exploit targets Microsoft Defender and works against fully patched Windows 10 and Windows 11 systems. 

    ThreatLocker, a U.S. based security firm, said it independently reproduced the exploit shortly after publication, confirming the flaw was real rather than theoretical, although its own allowlisting controls blocked the attack by default. An earlier version reportedly allowed full remote takeover through a Defender trick involving a virtual hard disk file. 

    After Microsoft changed Defender to close that route, the published version instead wins a race condition for local privilege escalation, giving an attacker with limited access full SYSTEM control.

    The Pattern Behind the Date

    This is the third consecutive month the researcher has timed a disclosure to Patch Tuesday. Two of the flaws Microsoft fixed in its June batch, GreenPlasma and MiniPlasma, had already been disclosed by the same researcher weeks earlier. Microsoft described MiniPlasma as a regression of a bug it had supposedly patched in 2020. 

    And RoguePlanet brings the researcher’s public zero day count to seven, following RedSun, UnDefend, BlueHammer and YellowKey, plus GreenPlasma and MiniPlasma. It is important to note that attackers actively exploited three of those earlier flaws soon after proof of concept code went public.

    Why Microsoft’s Bans Have Not Worked

    After a string of public exploit releases, the researcher’s repositories were removed from GitHub and later from GitLab. New accounts and repositories kept reappearing with the same code, and the researcher has since built independent hosting infrastructure to keep the exploits circulating outside platforms Microsoft or GitLab can moderate.

    Microsoft published a blog post in late May defending coordinated disclosure, arguing public releases without prior notice puts it in the hands of threat actors and noting none of the flaws had come through its official channels first. 

    However, Security researchers did not agree with Microsoft’s stance. Kevin Beaumont, a veteran researcher who previously worked at Microsoft, called the company’s position a “dumpster fire of Microsoft’s own making,” pointing how Microsoft once hired a researcher named SandboxEscaper after she released her own unpatched zero days, the same conduct it now describes as criminal. 

    The researcher briefly threatened a mass exploit dump for July 14, then walked it back, saying the work behind RoguePlanet had drained them. Whether that pause holds is unclear. What these series of bans, patches and public exploits have shown is that none of it has stopped the next one from arriving on schedule.

    cybersecurity GitHub GitLab Microsoft Defender Microsoft Security Response Center Nightmare Eclipse Patch Tuesday RoguePlanet SYSTEM privilege escalation ThreatLocker vulnerability disclosure Windows 10 Windows 11 Windows vulnerability Zero-day exploit
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    precious
    • LinkedIn

    I’m Precious Amusat, Phronews’ Content Writer. I conduct in-depth research and write on the latest developments in the tech industry, including trends in big tech, startups, cybersecurity, artificial intelligence and their global impacts. When I’m off the clock, you’ll find me cheering on women’s footy, curled up with a romance novel, or binge-watching crime thrillers.

    Related Posts

    Massive Pentagon Data Breach Exposes Records of Over 3 Million People

    October 8, 2026

    Salesforce Agentforce Flaws Allowed Hackers to Steal Data Without a Click

    October 8, 2026

    Google Reveals AI Is Discovering Increasingly Dangerous Software Vulnerabilities

    October 7, 2026

    Comments are closed.

    Top Posts

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 2025
    Don't Miss
    Cybersecurity & Online Safety

    Massive Pentagon Data Breach Exposes Records of Over 3 Million People

    By preciousOctober 8, 2026

    The Pentagon has confirmed that personal information belonging to more than 3 million people were…

    Why Amazon Wants Investors Buying $8 Billion of Its Nvidia Chips

    October 8, 2026

    Salesforce Agentforce Flaws Allowed Hackers to Steal Data Without a Click

    October 8, 2026

    Google Reveals AI Is Discovering Increasingly Dangerous Software Vulnerabilities

    October 7, 2026
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.