<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Microsoft on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/microsoft/</link><description>Recent content in Microsoft on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 14:30:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/microsoft/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Exploit Leak: Researcher Bypasses Disclosure</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-exploit-leak-researcher-bypasses-responsible-disclosure/</link><pubDate>Wed, 03 Jun 2026 14:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-exploit-leak-researcher-bypasses-responsible-disclosure/</guid><description>A bug hunter has publicly leaked Microsoft exploits in protest at Redmond&amp;#39;s disclosure handling, raising urgent patching concerns for Azure and Windows env</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/03/another-bug-hunter-leaks-microsoft-exploits-in-defiance-of-companys-handling-of-vulnerability-disclosures/5250590">The Register — Security</a></p>
<hr>
<p>A security researcher has publicly leaked Microsoft exploit code in protest at how the company handles vulnerability disclosures, following a similar incident by a researcher known as Nightmare Eclipse. The move bypasses responsible disclosure norms, meaning working exploits are now publicly available before Microsoft has necessarily issued patches. This significantly raises the risk for organisations running unpatched Microsoft and Azure environments.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your Microsoft and Azure patch status immediately and prioritise any outstanding security updates — publicly available exploit code dramatically shortens the window between disclosure and active exploitation. Ensure your vulnerability management process includes alerting on zero-day and pre-patch public exploit releases, not just CVE publication.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/03/another-bug-hunter-leaks-microsoft-exploits-in-defiance-of-companys-handling-of-vulnerability-disclosures/5250590">Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures</a></p>
]]></content:encoded></item><item><title>Microsoft Exploit Leaked: Researcher Bypasses Disclosure</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-exploit-leaked-researcher-defies-vulnerability-disclosure-process/</link><pubDate>Wed, 03 Jun 2026 14:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-exploit-leaked-researcher-defies-vulnerability-disclosure-process/</guid><description>A bug hunter has leaked Microsoft exploit code publicly, bypassing responsible disclosure. Cloud architects should patch Microsoft systems immediately.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/03/another-bug-hunter-leaks-microsoft-exploits-in-defiance-of-companys-handling-of-vulnerability-disclosures/5250590">The Register — Security</a></p>
<hr>
<p>A security researcher has publicly leaked Microsoft exploit code in protest at how the company handles vulnerability disclosures, following a similar incident by a researcher known as Nightmare Eclipse. The researcher chose to bypass responsible disclosure and release exploits immediately, arguing Microsoft&rsquo;s process is inadequate. This creates immediate risk as working exploit code is now publicly available before patches may be widely applied.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your Azure and Microsoft 365 patch status urgently and prioritise any outstanding Microsoft security updates, as publicly available exploit code significantly shortens the window between disclosure and active exploitation. Monitor Microsoft&rsquo;s Security Response Center and threat intelligence feeds closely for CVE details tied to these leaks.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/03/another-bug-hunter-leaks-microsoft-exploits-in-defiance-of-companys-handling-of-vulnerability-disclosures/5250590">Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures</a></p>
]]></content:encoded></item></channel></rss>