Microsoft Threatens Bug Researcher, Security Community Revolts

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft published an MSRC blog post implying a criminal referral and legal action against researcher "Nightmare Eclipse," who had published unpatched bugs in Microsoft products along with working exploit code
- The Register reports the "disgruntled" researcher was "humiliated" by Microsoft and pledged a "bone shattering drop" of further Windows exploit dumps in retaliation
- Microsoft's MSRC framed zero-day releases as "never justifiable," while the researcher publicly countered that Microsoft started the dispute, per Security Affairs
- Security researchers flooded X and Mastodon with their own negative MSRC experiences, with @vxunderground warning the community is "approaching the tipping point" and @arekfurt describing MSRC work as one of tech's "most utterly thankless jobs"
- Katie Moussouris, CEO of Luta Security, publicly sided with the researcher, telling The Register: "The bugs are Microsoft's. They wrote the code and they own the risk to customers"
- @zodttd alleged Microsoft ridiculed the researcher, deleted his account, and paid no bug bounties, while CERT/CC's Will Dormann (@wdormann) recounted a past dispute over MSRC treating CVE IDs as secret Patch Tuesday markers
Why it matters: This episode reveals a fracture in Microsoft's relationship with the security research community its patching model depends on. With @vxunderground warning the community is "approaching the tipping point" and Luta Security's Katie Moussouris publicly siding with the researcher, Microsoft's framing — that the bugs are theirs but public disclosure is irresponsible — is being rejected by the very researchers whose cooperation underpins coordinated disclosure. The researcher's pledge of a "bone shattering drop" of more unpatched exploits raises immediate risk for Windows users.
Ask SkimNews

