frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Microsoft 0-day feud escalates as researcher threatens another exploit dump

https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085
51•Cider9986•1h ago

Comments

rekabis•1h ago
I may not have seen the full story - and I am cognizant of this - but what I have seen so far puts me solidly on the side of Nightmare Eclipse.

Microsoft is making all indications that it is behaving like a colossal dick. It’s not a good look. As always: if you find yourself in a deep hole, stop digging.

zadkey•1h ago
Everything I've ready points to the same.
rolph•1h ago
there are active forks, and active mitigations for redsun undefend and bluehammer.

so far as i can tell yellowkey is problematic, as the exploit takes advantage of a backdoor that ms needs, to "manage" your computer.

only recently has a OOB mitigation been offered

https://www.techspot.com/news/112410-security-researcher-mic...

ranger_danger•17m ago
> backdoor that ms needs

source:

mittensc•11m ago
> so far as i can tell yellowkey is problematic, as the exploit takes advantage of a backdoor that ms needs, to "manage" your computer.

It does look like an intentional backdoor. The way ms is responding to it is even more suspicious.

Pretty funny since this defeats security on most corporate laptops, so impact is huge. You'd expect them to treat the reporter better and fix the issue fast...

I'm curious why they put it in, I'm not sure I understand the 'to "manage" your computer' note.

Microsoft should have no reason to put something like this in. So either they were forced or they had some engineers that did this on their own without any oversight.

8cvor6j844qw_d6•42m ago
> “CVD is a two-way street,” he said. “The vendor has some responsibility as well, so to go out publicly stating this person violated CVD without showing any of the correspondence seems bold.”

> “It confusingly claims their program ‘ensures researchers are compensated and publicly acknowledged’ in a statement answering a researcher who says he got neither,”

Well said.

ChrisArchitect•20m ago
Related:

GitHub bans security researcher who posted zero-day Windows exploits

https://news.ycombinator.com/item?id=48315968

45ahgd•7m ago
This is poor damage control by Microslop. Why would the researcher publish valuable exploits without trying to get a bounty?

Usually, when an individual is that upset, the group or corporation is wrong and tries to shape public perception by lying.

Since when is publishing zero days a crime anyway? Shame on Microslop for these intimidation tactics. The real crime is vibe coding operating systems.

midtake•5m ago
Sorry not sorry

The California State Assembly Has Passed the 'Protect Our Games Act'

https://www.invenglobal.com/articles/22330/stop-killing-games-movement-gains-momentum-california-...
90•TechTechTech•1h ago•57 comments

SQLite is all you need for durable workflows

https://obeli.sk/blog/sqlite-is-all-you-need-for-durable-workflows/
204•tomasol•3h ago•107 comments

The dead economy theory

https://www.owenmcgrann.com/p/the-dead-economy-theory
436•WillDaSilva•5h ago•595 comments

Notes from the Mistral AI Now Summit in Paris

https://koenvangilst.nl/lab/mistral-ai-now-summit
259•vnglst•4h ago•66 comments

On Rendering Diffs

https://pierre.computer/writing/on-rendering-diffs
79•amadeus•2h ago•26 comments

Shift will clean homes for free to train future robots

https://www.theverge.com/ai-artificial-intelligence/939765/ai-training-data-startup-shift-free-cl...
26•evilsimon•1h ago•36 comments

Bijou64: A variable-length integer encoding

https://www.inkandswitch.com/tangents/bijou64/
183•justinweiss•6h ago•67 comments

It's hard to justify buying a Framework 12

https://www.jeffgeerling.com/blog/2026/its-hard-to-justify-framework-12/
160•watermelon0•6h ago•284 comments

Show HN: Tiny-vLLM – high performance LLM inference engine in C++ and CUDA

https://github.com/jmaczan/tiny-vllm
25•yu3zhou4•1h ago•2 comments

Liquid AI reveals 8B-A1B MoE trained on 38T

https://www.liquid.ai/blog/lfm2-5-8b-a1b
91•simjnd•4h ago•23 comments

Rothko for your current weather conditions

https://rothko.joonas.wtf/
81•jxmorris12•2h ago•9 comments

Why I collect DLES

https://dles.gg/blog/dles-gg-manifesto
9•trizoza•35m ago•2 comments

GTA 6 Developers Unionize

https://rockstarintel.com/gta-6-developers-announce-rockstar-games-union/
474•AndrewKemendo•5h ago•300 comments

Show HN: TV Explorer. Adding advanced UI to free online TV

https://tvexplorer.live
71•dtagames•4h ago•16 comments

Is AI causing a repeat of frontend’s lost decade?

https://mastrojs.github.io/blog/2026-05-23-is-AI-causing-a-repeat-of-frontends-lost-decade/
232•xyzal•10h ago•205 comments

A Trillion Characters

https://characters.fastserial.com
11•andersmurphy•43m ago•9 comments

Letter from the Duke of Wellington to the British Foreign Office (1809)

https://wellsoc.org/society-member-pages/anecdotes-of-wellington/
30•backuprestore•3h ago•6 comments

CAPTCHAs can still detect AI agents

https://research.roundtable.ai/captchas-detect-ai/
54•timshell•5h ago•39 comments

We should be more tired than the model

https://vickiboykis.com/2026/05/28/we-should-be-more-tired-than-the-model/
131•tosh•9h ago•113 comments

High Density Living, 2000 Years Ago: Inside the Roman Apartment Building

https://commonedge.org/high-density-living-2000-years-ago-inside-the-roman-apartment-building/
135•surprisetalk•8h ago•52 comments

Robinhood now lets your AI agents trade stocks

https://techcrunch.com/2026/05/27/robinhood-now-lets-your-ai-agents-trade-stocks/
73•wapasta•3h ago•128 comments

Microsoft 0-day feud escalates as researcher threatens another exploit dump

https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-thre...
53•Cider9986•1h ago•9 comments

I am retiring from tech to live offline

https://openpath.quest/2026/i-am-retiring-from-tech-to-live-offline/
667•PinkG•6h ago•456 comments

Someone used my open source project to phish people

https://andrej.sh/posts/phishing-through-my-open-source-project
76•andrejsshell•7h ago•46 comments

Cedana (YC S23) Is Hiring

https://www.ycombinator.com/companies/cedana/jobs/d1vYocG-forward-deployed-engineer-ai-hpc
1•neelm•9h ago

Notable Properties of Specific Numbers

http://www.mrob.com/pub/math/numbers-19.html
5•rolph•2d ago•0 comments

Local Git remotes

https://cblgh.org/posts/local-git-remotes/
78•surprisetalk•8h ago•64 comments

Canada in Technical Recession

https://www.cbc.ca/news/business/recession-gdp-may-2026-statscan-9.7216352
28•efavdb•52m ago•10 comments

Expertise in the age of AI

https://www.moderndescartes.com/essays/ai_and_expertise/
88•brilee•7h ago•89 comments

Real-time LLM Inference on Standard GPUs: 3k tokens/s per request

https://blog.kog.ai/real-time-llm-inference-on-standard-gpus-3-000-tokens-s-per-request/
189•NicoConstant•11h ago•86 comments