Researcher Publishes Code to Exploit Windows Vulnerabilities

As part of a practice called "full disclosure," researchers will find flaws in a software and report them to the software maker to help resolve them. However, in some cases where communication between the two parties fail, the researcher may choose to publicly disclose information about the bug instead. This seems to be the case for a researcher called Chaotic Eclipse, who published code on GitHub that allowed individuals to exploit three Windows vulnerabilities, dubbed BlueHammer, UnDefend, and RedSun. Since then, hackers have used Chaotic Eclipse's code to break into organizations through Window's security flaws, demonstrating the dangers of what could happen from publishing security vulnerabilities on the Internet. So far, BlueHammer is the only bug that has been patched by Microsoft.