The Patch Tuesday With One Author
Microsoft shipped its largest Patch Tuesday on record, and the one flaw already under attack was dropped on purpose by a single researcher who says the company made him do it. The week's biggest security event is a labor dispute.
Summary
Microsoft shipped its largest Patch Tuesday on record this week, more than two hundred fixes in a single release. The one flaw already under active attack, a Windows Defender privilege bug tagged CVE-2026-41091, did not come from a crime syndicate or a foreign service. A single researcher dropped it on purpose, and he says Microsoft is the reason he did. The biggest security event of the week is a labor dispute that spilled into everybody's network.
Findings
The researcher goes by Nightmare Eclipse, sometimes Chaotic Eclipse. Rumor puts him inside Microsoft at some point, though nobody has confirmed it. His account has held steady from the first post. He filed his bugs through the official channel and watched the reports come back ignored or rejected, and Microsoft deleted his submission account without paying him a dollar and then flagged his GitHub for takedown. So he stopped asking.
Then he went to work in the open. Over the past several weeks he has published one working exploit after another, with no coordinated disclosure and no warning. He dropped BlueHammer first, then RedSun, which is the same CVE-2026-41091 that Microsoft had just scrambled to patch. UnDefend followed, and after it RoguePlanet, which hands an attacker SYSTEM on a fully updated Windows box. Days after the patch shipped he put out GreatXML, a claimed BitLocker bypass that other researchers say does not reliably work yet.
Microsoft calls the dumps irresponsible and notes that none of them came through official channels first, and he answers that Microsoft started it. The damage is real, and the Defender bugs are being exploited in the wild right now. He has already teased the next release for 14 Jul 26.
Impact
The software sold to protect the machine is where the holes sit this week. Defender is supposed to guard the endpoint, and this week it is the thing handing out SYSTEM. BitLocker is supposed to guard the data, and this week it is the one under challenge. Every defense contractor under CMMC leans on exactly those two controls to protect controlled unclassified information, so this lands square on the regulated base along with everybody's home machines.
Under the CVEs sits an older story. Joel Bakan argued that the law makes a corporation a legal person, and that the person it produces behaves like a psychopath, because its charter tells it to maximize its own return and the law nudges it to never surrender a dollar on principle. A company built that way treats the people who secure its product as something it gets for free, and that holds right up until one of them decides to start charging in public.
You can see the same public mood around Luigi Mangione, who is back in court in Manhattan this week, recast by strangers as a folk hero, furious at a different giant entirely. Both stories carry real victims, and naming what the two share is a long way from cheering it. The common part is that labor a company ignores will come back on it with a price attached, and this week the price landed on everyone who runs Windows.
Recommendations
Start with the patch queue, and push CVE-2026-41091 and this week's additions to the CISA exploited list ahead of anything cosmetic. Stop treating Defender and BitLocker as the whole defense, because they are one layer and this week showed a layer can fail in the attacker's favor. Segment the network and watch the endpoints as if the local control is already owned, and put 14 Jul 26 on the calendar.
Now the harder one, for anyone who runs a disclosure program. Answer the researchers who report to you and pay the ones who earn it, because a reporting process left to rot saves almost nothing. Microsoft saved itself some bounty money on this one, and every admin pushing two hundred fixes this week is covering the difference.
Works Cited
- Lawrence Abrams, Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws (BleepingComputer, 9 Jun 26)
- Microsoft smashes record for biggest ever Patch Tuesday update (Computer Weekly, Jun 26)
- Nightmare Eclipse publishes new Windows Defender zero-day (The Register, 10 Jun 26)
- Nightmare-Eclipse: six zero-days, six weeks and one big grudge (Barracuda Networks Blog, 19 May 26)
- Microsoft Defender vulnerabilities exploited in the wild, CVE-2026-41091 and CVE-2026-45498 (Help Net Security, 21 May 26)
- Microsoft Calls the Zero-Day Dumps Irresponsible. The Researcher Says Microsoft Started It. (Security Affairs, 29 May 26)
- GreatXML zero-day BitLocker bypass doesn't seem to work, yet (CSO Online, Jun 26)
- CISA Adds Three Known Exploited Vulnerabilities to Catalog (CISA, 9 Jun 26)
- Brian Mann, As Luigi Mangione's lawyers head to court, support grows for the accused 'vigilante' (NPR, 15 Jun 26)
- Joel Bakan, The Corporation: The Pathological Pursuit of Profit and Power (Free Press, 2004)