Microsoft Threatens Researcher Over Zero‑Day Bugs

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft posted a blog that suggested criminal referral and legal action against security researcher Nightmare Eclipse after he publicly disclosed a series of unpatched bugs and exploit code for Microsoft products.
- Nightmare Eclipse responded by threatening to release more zero‑day vulnerabilities and accusing Microsoft of initiating the conflict, while calling Microsoft’s stance on zero‑day disclosures “irresponsible.”
- Microsoft reiterated its policy that “zero‑day releases are never justifiable” in a separate blog titled “A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure.”
- Security researchers (including accounts like @rootsecdev and @gabriellandau) reported that Microsoft sometimes declines to assign CVE IDs or consider issues “unserviceable,” even when patches are released, and that the company’s communication can be delayed or opaque.
- Industry observers (e.g., The Register, PCMag) noted that Microsoft’s aggressive language and threats have alienated the security community, with many researchers calling the vendor’s approach “a dumpster fire” and “thankless.”
- Microsoft faced criticism across multiple outlets (TechCrunch, The Register, CSO, PCMag) for what they described as “irresponsible” handling of vulnerability disclosures, leading to a broader debate about coordinated vulnerability disclosure practices.
Why it matters: The dispute hurts Microsoft’s reputation among security researchers and slows coordinated vulnerability reporting, while researchers lose a collaborative channel for responsibly disclosing flaws. The clash also highlights gaps in Microsoft’s CVE assignment and compensation practices, prompting policy revisions and underscoring the need for clearer disclosure frameworks.
Ask SkimNews

