Microsoft's Record Patch Day Traces Back to One Angry Researcher
Microsoft shipped its biggest patch release ever, and the one bug already under attack was published on purpose by a single researcher. He says Microsoft made him do it.
Summary
Microsoft releases fixes for its software on the second Tuesday of every month. The industry calls it Patch Tuesday. Lawrence Abrams at BleepingComputer reports the June release was the largest one ever, with more than 200 bugs fixed. One bug in the batch was already being used in real attacks. It sits in Windows Defender, the security program built into Windows, under the bug number CVE-2026-41091. The bug did not leak from a crime group or a foreign government. A single researcher put it out on purpose, and he points at Microsoft as the reason. The week's biggest security story is a labor dispute.
Findings
The researcher calls himself Nightmare Eclipse, and sometimes Chaotic Eclipse. Rumor says he once worked inside Microsoft, though nobody has confirmed that. His story has held steady from the first post. He says he sent his bug reports through Microsoft's official channel and watched them get ignored or rejected. He says Microsoft then erased his submission account, paid him nothing, and flagged his code pages for removal. So he quit asking.
Then he went public. For weeks now he has released one working attack after another, with no warning to Microsoft. He names each release. BlueHammer came first. RedSun followed, and it is the same Defender bug Microsoft just patched. Then came UnDefend, then RoguePlanet, which gives an attacker full control of a fully updated Windows machine. Days after the patch went out he posted GreatXML, a claimed way around BitLocker, the tool built into Windows that locks the drive. CSO Online reports that other researchers cannot make GreatXML work so far.
Microsoft calls the releases irresponsible, and points out that none of them arrived through official channels first. The researcher's answer is that Microsoft started the fight. The damage is real either way. Help Net Security reports live attacks using the Defender bugs as of this writing. He has already promised another release on 14 Jul 26.
Impact
This week the holes sit inside the security software itself. Defender's whole job is guarding the computer, and this week it is what hands over control. BitLocker exists to guard the data, and this week it is the one in question. Defense contractors feel it hardest. The Cybersecurity Maturity Model Certification (CMMC) is the set of security rules defense contractors must meet. Those rules lean on exactly these two tools to protect sensitive government data.
Under the bug numbers sits an older story. Joel Bakan is a law professor who wrote a book called The Corporation in 2004. He argued that the law treats a corporation as a person. The person it creates acts without a conscience, he wrote. Its charter orders it to maximize return and never hand a dollar back on principle. A company shaped like that treats the researchers who lock down its product as free labor. That holds right up until one of them starts charging in public.
The same public mood surrounds Luigi Mangione, the man accused of killing the UnitedHealthcare chief executive in Dec 24. NPR reports his case returned to a Manhattan courtroom this week while strangers treat him as a folk hero, angry at a different giant company. There are real victims in both stories, and pointing out what they share is far from cheering it. The shared part is plain. When a company ignores the people whose work protects it, the cost arrives later. This week it arrived for everyone who runs Windows.
Recommendations
Patch CVE-2026-41091 first. Then take the three bugs the Cybersecurity and Infrastructure Security Agency (CISA) flagged on 9 Jun 26 as already under attack. Quit counting on Defender and BitLocker alone, because this week one protective layer worked in the attacker's favor. Split the network into sections and watch each machine as if its local protection is already beaten. Mark 14 Jul 26 on the calendar.
Here is the harder job, for anyone running a program that takes bug reports. Answer the researchers who write in, and pay the ones who earn it. A reporting process that goes unanswered saves almost nothing. Microsoft kept some bounty money here, and every admin pushing 200 fixes this week is paying the difference.
Works Cited
- Lawrence Abrams, Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws (BleepingComputer, 9 Jun 26)
- Microsoft smashes record for biggest ever Patch Tuesday update (Computer Weekly, Jun 26)
- Nightmare Eclipse publishes new Windows Defender zero-day (The Register, 10 Jun 26)
- Nightmare-Eclipse: six zero-days, six weeks and one big grudge (Barracuda Networks Blog, 19 May 26)
- Microsoft Defender vulnerabilities exploited in the wild, CVE-2026-41091 and CVE-2026-45498 (Help Net Security, 21 May 26)
- Microsoft Calls the Zero-Day Dumps Irresponsible. The Researcher Says Microsoft Started It. (Security Affairs, 29 May 26)
- GreatXML zero-day BitLocker bypass doesn't seem to work, yet (CSO Online, Jun 26)
- CISA Adds Three Known Exploited Vulnerabilities to Catalog (CISA, 9 Jun 26)
- Brian Mann, As Luigi Mangione's lawyers head to court, support grows for the accused 'vigilante' (NPR, 15 Jun 26)
- Joel Bakan, The Corporation: The Pathological Pursuit of Profit and Power (Free Press, 2004)