Microsoft threatens researcher over zero‑day disclosures

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft posted a blog entry that warned the security researcher Nightmare Eclipse of possible criminal investigation and legal action after the researcher publicly disclosed unpatched bugs and exploit code for Microsoft products.
- Nightmare Eclipse released a series of zero‑day vulnerabilities and accompanying exploit code, which Microsoft labeled as “irresponsible” and “never justifiable.”
- Security community reacted with widespread criticism, with many researchers on X and other platforms condemning Microsoft’s threat as heavy‑handed and calling for a more collaborative disclosure process.
- Microsoft’s “shared responsibility” blog emphasized coordinated vulnerability disclosure, and the company has called zero‑day releases “never justifiable.”
- Nightmare Eclipse asserted that Microsoft had previously changed its “servicing” criteria, patching a vulnerability without issuing a CVE, and claimed the company “started” the dispute.
- Researcher threatened to publish additional zero‑day exploits if Microsoft continued its current stance, escalating the conflict.
- Multiple media outlets (TechCrunch, CSO, The Register, PCMag, etc.) reported the clash, highlighting both Microsoft’s stance on responsible disclosure and the researcher’s grievances with Microsoft’s handling of vulnerability reports.
Why it matters: The clash underscores a growing rift between big‑tech vendors and independent security researchers; Microsoft’s aggressive warning may deter future disclosures, while researchers risk being silenced, potentially leaving customers exposed to unpatched flaws. Community backlash could force Microsoft to rethink its vulnerability‑handling policies.
Ask SkimNews

