Microsoft Threatens to Sue Zero‑Day Hacker

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft is being criticized for its handling of zero‑day exploits after a hacker posted proof‑of‑concept code.
- Nightmare Eclipse has publicly feuded with Microsoft, posting a proof‑of‑concept exploit and suggesting they may be a disgruntled former employee.
- Microsoft plans to bring a criminal case against Nightmare Eclipse for not following “proper coordination” in vulnerability disclosure and has disabled the hacker’s GitHub, GitLab, and Microsoft Security Response Center accounts.
- Kevin Beaumont points out that Microsoft’s own hiring of individuals who have previously posted zero‑day exploits, some with criminal convictions, and its purchase of exploits from brokers undermine its “responsible disclosure” stance.
- Beaumont warns that Microsoft’s tactic to criminalize non‑compliance with its disclosure framework could be hard to defend in court given its own contradictory past practices.
Why it matters: Security researchers lose a viable channel for reporting flaws as Microsoft bans the hacker and threatens prosecution, while Microsoft’s credibility erodes because it employs former exploiters and buys zero‑day bugs, raising questions about the fairness of its disclosure policy and accountability.
Ask SkimNews

