Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Spotify’s reserved ticket sales to music superfans are now live

‘Queer Eye’ life coach Karamo Brown launches Kē, a wellness app featuring his digital AI clone

Waymo recalls nearly 4,000 robotaxis to stop them from driving in highway construction zones

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    General Intuition in talks to raise $300M at roughly $2B valuation

    18 June 2026

    How to turn off AI in your Google Docs

    18 June 2026

    SpaceX values ​​balloons at $2.6T, narrowly passes Amazon

    17 June 2026

    SpaceX Goes Public: Everything You Need to Know Post-IPO

    16 June 2026

    Sundar Pichai faces backlash, pulls out of Stanford graduation ceremony for Google’s Israel, ICE ties

    16 June 2026
  • Apps

    MapTap, an everyday geography game, is my new Wordle

    18 June 2026

    FTC Lawsuit Reveals How Subscription Scam Networks Avoid App Store Enforcement

    18 June 2026

    Pinterest Launches Experimental AI Shopping App Called ‘Ask Pinterest’

    17 June 2026

    Android 17 rolls out with new multitasking tools as Google expands Gemini features

    17 June 2026

    India orders temporary ban on Telegram over exam cheating

    16 June 2026
  • Crypto

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026
  • Fintech

    Robinhood’s note on 10% layoffs shows that blaming AI doesn’t cut it

    17 June 2026

    Anthropic’s latest spat with the Trump administration may actually help it, sales figures suggest

    17 June 2026

    Ramp raises $750M at $44B valuation as investors thirst for fintechs with AI history

    5 June 2026

    Last 24 hours to save up to $410 on your Disrupt 2026 ticket

    29 May 2026

    2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

    28 May 2026
  • Hardware

    AI hurts Apple in more ways than one: It could force iPhone price hikes

    18 June 2026

    Snap is finally debuting its long-awaited AR glasses, the specs, and, ugh, they’re not cheap

    17 June 2026

    Qualcomm wants to be the chip in everything that replaces your smartphone, and it just announced two products to that end

    17 June 2026

    This slim speaker under the pillow helped me sleep without headphones

    14 June 2026

    Jeff Bezos’ Prometheus Raises $12 Billion to Build an ‘Artificial General Engineer’ for the Natural World

    12 June 2026
  • Media & Entertainment

    Spotify’s reserved ticket sales to music superfans are now live

    18 June 2026

    Google is betting on Gemini to reinvent the smart home speaker

    18 June 2026

    Mastodon is looking for newsletters to help revive the open social web

    17 June 2026

    60 percent of US consumers say ‘artificial intelligence’ in brand messaging is a turnoff, survey finds

    16 June 2026

    Fox to acquire Roku in $22 billion deal

    15 June 2026
  • Security

    Cybercriminals reportedly hacked tens of thousands of Fortinet firewalls used by major companies around the world

    17 June 2026

    Apple is planning to change the Hide My Email privacy feature that could make it less effective

    17 June 2026

    The US government’s ban on Anthropic models was never about an AI jailbreak

    16 June 2026

    As AI agents become employees, NewCore comes up with $66 million to give them identities

    15 June 2026

    The FBI built its own replica small town to simulate real-world cyberattacks

    13 June 2026
  • Startups

    ‘Queer Eye’ life coach Karamo Brown launches Kē, a wellness app featuring his digital AI clone

    18 June 2026

    Pramaana Labs Raises $27M From Khosla Ventures To Bring Official Verification To Artificial Intelligence

    18 June 2026

    Collecting bot training data is dirty, unsavory work. Some AI labs already pay XDOF to do it.

    17 June 2026

    This startup’s super metals could soon be found in military drones, luxury watches and chef’s knives

    17 June 2026

    He’s probably raising $9 million to create a more reliable kind of AI

    16 June 2026
  • Transportation

    Waymo recalls nearly 4,000 robotaxis to stop them from driving in highway construction zones

    18 June 2026

    Uber will bring its premium robotaxi service to Houston in 2027

    17 June 2026

    Mobileye’s robotaxi launch in the US will put it on both sides of the AV business

    17 June 2026

    SpaceX Goes Public: Everything You Need to Know Post-IPO

    16 June 2026

    GM is joining the race to make batteries for AI data centers and the grid

    15 June 2026
  • Venture

    Roelof Botha joins SpaceX board of directors

    18 June 2026

    Chi-Hua Chien saw Facebook coming – now he says the real AI winners won’t sell AI

    18 June 2026

    PayPal Ventures is shutting down as the company continues to restructure

    17 June 2026

    Orbio raises $21 million to automate hiring and onboarding of frontline workers

    15 June 2026

    Why business AI will be the focus of VivaTech 2026

    10 June 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Microsoft is under fire for threatening a security researcher with a criminal investigation
Security

Microsoft is under fire for threatening a security researcher with a criminal investigation

techtost.comBy techtost.com29 May 202604 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Microsoft Is Under Fire For Threatening A Security Researcher With
Share
Facebook Twitter LinkedIn Pinterest Email

After a security researcher published a series of unpatched bugs in Microsoft products, along with code to exploit them, the company is now threatening legal action and calling the police to deal with them. Microsoft’s veiled threat rekindles a long-running argument about the responsibility, if any, of security researchers to uncover vulnerabilities affecting large and wealthy tech giants.

On Wednesday, Microsoft published a blog post criticizing the researcher, who says “Nightmare Eclipse”, for publicly revealing a number of bugs, such as BlueHammer, RedSun, UnDefendand YellowKey. The flaws affected products such as Windows Defender’s built-in antivirus engine and the BitLocker disk encryption tool.

The core of Microsoft’s complaints is that the researcher didn’t try to report the bugs so the company could fix them. That would be “responsible,” as Microsoft’s blog put it. The other side of the company’s argument is that by publishing the details of the bugs and how to exploit them before they were patched, Nightmare Eclipse may have aided malicious hackers. Some of the vulnerabilities revealed by Nightmare Eclipse have since been used by hackers in real attacks, according to Microsoft, as well as the US cybersecurity agency CISA.

“Our Digital Crimes Unit will continue to prosecute these actors and those who enable their criminal activity — coordinating as necessary with law enforcement around the world,” Microsoft wrote. (Microsoft’s Digital Crimes Unit is tasked with protecting the company through different strategies, including “civil lawsuits, technical countermeasures, criminal referrals, and public-private partnerships,” according to its website).

In one blog series Nightmare Eclipse published in the past two weeks — without providing many specific details — claimed to have been in contact with Microsoft, but the company allegedly mistreated them, including revoking their account access to the Microsoft Security Response Center, the portal where researchers can report vulnerabilities to the tech giant. The implication of Nightmare Eclipse was that they had no choice but to release the vulnerabilities publicly, which essentially meant that at that point they were zero-days, a specific term for security flaws that are unknown to the affected software manufacturer at the time they are discovered or exploited.

The researchers published the bugs in open source repositories GitHub (the property of Microsoft) and GitLab. Researchers’ accounts on these platforms have been banned.

Nightmare Eclipse and Microsoft did not respond to a request for comment.

Cybersecurity veterans warn of a chilling outcome

This public spat brings back a long-standing and still somewhat contentious debate: Do independent security researchers have a duty to ensure that the vulnerabilities they find are patched? And how far should they go to make sure that companies whose products are vulnerable actually fix them?

One part of this debate, which has been fully settled and widely acknowledged, is that researchers deserve to be paid for their work. While it may sound obvious these days, it took years of struggle, captured in part during a campaign launched in 2009 titled “No more free bugs.” Nearly 20 years later, most small and large companies pay “bug bounties,” which today can run into six figures or more, to researchers who uncover private bugs and coordinate the publication of their data once the bugs are fixed.

In response to this latest feud with Nightmare Eclipse, countless researchers have shared their bad experiences by reporting bugs to Microsoft. It’s fair to say that much of the cybersecurity community is vocally unhappy with Microsoft’s handling of this issue. That includes cybersecurity veterans like Katie Moussouris, founder of Luta Security, who while working at Microsoft in the mid-to-late 2000s pioneered bug bounties and convinced the tech giant to move away from the concept of “responsible disclosure” by framing the process as “coordinated disclosure.”

“Invoking the term ‘responsible’ disclosure was the first strike in my book,” Moussouris told TechCrunch, referring to Microsoft’s blog post. “Adding threat of prosecution by reporting [Digital Crimes Unit] was over the top and will only result in security researchers not trusting Microsoft.”

Moussouris warned that the consequences of security researchers losing trust with Microsoft could have the chilling effect of fewer people reporting bugs, “making it less secure for all of us.”

Security researcher and former Microsoft employee Kevin Beaumont he also called out Microsoft in a blog postdescribing the company’s position as a “garbage fire of its own making”.

“Proof of concept exploit creation and distribution for zero days is ‘criminal activity’ now?” Beaumont wrote. “Responsible disclosure is often framed to protect the product owner rather than the customer – using it to try to prosecute people is a new low.”

When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.

bounties bug Criminal cyber security Fire hacker investigation Microsoft researcher security threatening Zero-days
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCognition’s Scott Wu says AI coding agents shouldn’t replace humans
Next Article YouTube adds new podcast features, including an AI recommendation tool and ‘Auto Speed’
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Cybercriminals reportedly hacked tens of thousands of Fortinet firewalls used by major companies around the world

17 June 2026

Apple is planning to change the Hide My Email privacy feature that could make it less effective

17 June 2026

The US government’s ban on Anthropic models was never about an AI jailbreak

16 June 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Spotify’s reserved ticket sales to music superfans are now live

18 June 2026

‘Queer Eye’ life coach Karamo Brown launches Kē, a wellness app featuring his digital AI clone

18 June 2026

Waymo recalls nearly 4,000 robotaxis to stop them from driving in highway construction zones

18 June 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Robinhood’s note on 10% layoffs shows that blaming AI doesn’t cut it

17 June 2026

Anthropic’s latest spat with the Trump administration may actually help it, sales figures suggest

17 June 2026

Ramp raises $750M at $44B valuation as investors thirst for fintechs with AI history

5 June 2026
Startups

‘Queer Eye’ life coach Karamo Brown launches Kē, a wellness app featuring his digital AI clone

Pramaana Labs Raises $27M From Khosla Ventures To Bring Official Verification To Artificial Intelligence

Collecting bot training data is dirty, unsavory work. Some AI labs already pay XDOF to do it.

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.