Microsoft Threatens Researcher Over Bug Disclosures

SkimNews Take
AI hyperscalers' indirect engagement with FERC, through complaints about utilities, suggests a strategic effort to shape regulatory outcomes without directly revealing their specific infrastructure plans or energy demands.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft posted a blog warning that implied a criminal referral and possible legal action against security researcher Nightmare Eclipse after he publicly disclosed unpatched bugs and exploit code for Microsoft products.
- Nightmare Eclipse had published a series of unpatched vulnerabilities and associated exploit code, prompting Microsoft’s response.
- Microsoft described zero‑day releases as “never justifiable” and warned that such disclosures are irresponsible.
- Nightmare Eclipse threatened to release additional exploits if Microsoft does not address his concerns, escalating the dispute.
- Multiple media outlets including TechCrunch, The Register, PCMag, and Security Affairs reported on the conflict, highlighting the tension between vendor policies and independent researchers.
- Microsoft’s Security Response Center (MSRC) issued a blog titled “A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure,” framing the issue as a coordinated disclosure problem.
Why it matters: The clash pits Microsoft’s coordinated‑disclosure policy against independent researchers, eroding trust in bug‑reporting channels; security researchers lose a safe outlet for disclosures while customers risk exposure to unpatched vulnerabilities, and Microsoft’s reputation suffers amid criticism of its handling of zero‑day reports.
Ask SkimNews

