Microsoft Threatens Researcher Over Zero‑Day Bugs

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft published a blog post titled “A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure,” warning that publishing unpatched zero‑day bugs could be “irresponsible” and suggesting a criminal investigation of researcher Nightmare Eclipse.
- Microsoft called the researcher’s zero‑day releases “never justifiable” and warned that continued public disclosures could lead to legal action.
- Nightmare Eclipse responded by threatening to release additional Windows exploits, claiming Microsoft “started it” and that the company’s stance “humiliated” him.
- Security community on X and other platforms expressed outrage, with users criticizing Microsoft for “breaking the good‑faith disclosure social contract.”
- The Register reported that the researcher pledged a “bone‑shattering drop” of more zero‑days as retaliation.
- PCMag noted that Microsoft’s threat triggered a broader cybersecurity uproar, highlighting tension between coordinated disclosure and public bug reporting.
Why it matters: The dispute pits Microsoft’s push for coordinated fixes against a researcher’s public‑release strategy, risking legal exposure for the researcher while potentially leaving customers vulnerable if more zero‑days are dropped, and it has ignited a broader debate over responsible vulnerability disclosure.
Ask SkimNews

