Monday, August 3, 2026

Policy & Regulation

Microsoft threatens legal action against security researcher

Microsoft is threatening legal action against a security researcher who published unpatched bugs, sparking industry backlash over the company's handling of vulnerability disclosures.

Microsoft threatens legal action against security researcher

On Wednesday, Microsoft published a blog post criticizing a security researcher known as Nightmare Eclipse for publicly disclosing a series of bugs without reporting them to the company first. The tech giant is threatening to take legal action and call the cops on the researcher. Microsoft warned that its Digital Crimes Unit—the company’s internal division for legal and enforcement actions—will continue bringing cases against these actors and those that enable their criminal activity, coordinating as needed with law enforcement around the world. Microsoft claims that by publishing details of the bugs before they were patched, Nightmare Eclipse may have aided malicious hackers. According to Microsoft and the U.S. cybersecurity agency CISA, some of the vulnerabilities disclosed by Nightmare Eclipse have already been used by hackers in real-world attacks.

In a series of blogs published in the last couple of weeks, Nightmare Eclipse claimed they had been in contact with Microsoft, but the company allegedly mistreated them, including revoking access to their Microsoft Security Response Center account, the portal where researchers report vulnerabilities. The researcher subsequently published the bugs on open-source repositories GitHub, which is owned by Microsoft, and GitLab. Both platforms have since banned the researcher’s accounts. Because the flaws were disclosed without patches, they became zero-days, the term for security flaws unknown to the software maker at the time of disclosure.

The dispute has triggered widespread criticism from the cybersecurity community, reviving a debate that dates back to 2009 when a campaign called No More Free Bugs was launched. Almost 20 years later, most companies pay bug bounty rewards—which are financial rewards for reporting bugs that can run as high as six figures or more—to researchers who privately disclose vulnerabilities. Cybersecurity veterans are criticizing Microsoft’s insistence on responsible disclosure, the industry term for reporting bugs to vendors. Katie Moussouris, the founder of Luta Security who previously convinced Microsoft to adopt coordinated disclosure instead, warned that the threat of prosecution will create a chilling effect. “Adding a threat of prosecution by mentioning [Digital Crimes Unit] was over the top, and will only result in security researchers distrusting Microsoft,” Moussouris said. Kevin Beaumont, a security researcher and former Microsoft employee, also criticized the company’s stance as a dumpster fire of its own making, arguing that using the process to try to criminally prosecute people is a new low.

Why it matters

Microsoft’s aggressive stance reignites a long-standing debate over the responsibilities of security researchers versus the obligations of tech giants to handle vulnerability disclosures without resorting to legal threats.