Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Phia Accused of ‘Cookie Stuffing’, Taking Affiliate Credit for Unearned Purchases

Filed Under: College Fizz App Accuses VC Of Sharing Confidential Startup Info With Rival Sidechat

Meta removes controversial AI feature on Instagram after backlash

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Meta removes controversial AI feature on Instagram after backlash

    11 July 2026

    OpenAI launches its new family of models with GPT-5.6

    10 July 2026

    Fidji Simo resigns from the no. 2 role

    10 July 2026

    Nvidia is a victim of the PC market it created

    9 July 2026

    Google’s deepfake detection system used to debunk McConnell’s hoax

    9 July 2026
  • Apps

    Apple is suing OpenAI for alleged trade secret theft

    11 July 2026

    EU threatens Meta with fines for addictive features on Facebook and Instagram

    10 July 2026

    Instagram users: Here’s how to stop Meta’s AI from using your photos

    10 July 2026

    Anthropic’s new Claude ability quietly sells you on the AI

    9 July 2026

    Truecaller clashes with India’s telecom regulator over anti-spam rules

    9 July 2026
  • Crypto

    Venice AI goes unicorn with $65M Series A as first privacy AI platform takes off

    1 July 2026

    Crypto Exchange OKX wants AI agents to hire and pay each other

    30 June 2026

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026
  • Fintech

    Don’t want to invest in Elon Musk? Two new ETFs expressly exclude him

    10 July 2026

    India’s payments chief believes artificial intelligence will play a big part in the next era of digital payments development

    28 June 2026

    Early Bird pricing ends tonight for the Founder Summit

    26 June 2026

    4 days left to save up to $190 on Founder Summit 2026

    23 June 2026

    Robinhood’s note on 10% layoffs shows that blaming AI doesn’t cut it

    17 June 2026
  • Hardware

    SK Hynix raises $26.5 billion in largest foreign public IPO in US history, set to build new fabs in US

    11 July 2026

    After Apple, smartphone manufacturing boom in India enters new phase with Vivo JV

    10 July 2026

    Elon Musk praises Mythos/Fable, promises not to ‘cut’ Anthropic

    10 July 2026

    US investors will soon have access to SK Hynix, another memory maker driving the AI ​​boom

    7 July 2026

    Smart glasses maker Even Realities hits $1 billion valuation with $150 million in funding led by Meituan, Tencent

    6 July 2026
  • Media & Entertainment

    Netflix could be planning “always on” live TV channels.

    11 July 2026

    Netflix is ​​dealing with shorter video content with its new set of publisher deals with Variety and others

    8 July 2026

    Netflix invented binge watching. Now he may be over it.

    7 July 2026

    New Google ad imagines a Declaration of Independence written with the help of artificial intelligence

    4 July 2026

    Cloudflare’s new policy pushes AI companies to pay for publishers’ content

    1 July 2026
  • Security

    Florida ransomware dealer convicted of helping ransomware gang extort US companies

    10 July 2026

    Hacktivists call out Trump by hacking and defacing US military websites

    8 July 2026

    Canada’s spy agency says it hacked drug traffickers, extremists and a ransomware gang last year

    6 July 2026

    Politician who investigated abuses of wiretapping software on his phone with Pegasus spyware

    3 July 2026

    The US government says it’s been hacked — again

    2 July 2026
  • Startups

    Phia Accused of ‘Cookie Stuffing’, Taking Affiliate Credit for Unearned Purchases

    11 July 2026

    Oratomic raises $300M to build sustainable quantum computer that only needs 20,000 qubits

    10 July 2026

    These AI startups are growing revenue at an ever-faster pace

    10 July 2026

    Popular Open Source AI Developer Tool Ollama Raises $65M, Grows to Nearly 9M Users

    9 July 2026

    With EU support, QuantumDiamonds aims to accelerate chip manufacturing

    9 July 2026
  • Transportation

    Slate Auto partners with Crayola to paint its EV truck

    10 July 2026

    Autonomous drone delivery startup Manna plans major US expansion

    9 July 2026

    Federal authorities are demanding that autonomous vehicle companies stop interfering with first responders

    9 July 2026

    Another massive data breach exposed millions of driver’s license numbers

    8 July 2026

    This startup brings dealers together to bid on your used car

    7 July 2026
  • Venture

    Filed Under: College Fizz App Accuses VC Of Sharing Confidential Startup Info With Rival Sidechat

    11 July 2026

    Charles Hudson shares the common mistakes he’s seen after investing in 500+ startups

    10 July 2026

    Nandan Nilekani steps down as GP at Fundamentum as it launches third $200m fund

    9 July 2026

    What are bending spoons? The little-known owner of AOL and Vimeo who is now public

    5 July 2026

    After $18B IPO, Bending Spoons Founder Says Success Comes From Minimizing Luck

    2 July 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Microsoft is under fire for threatening a security researcher with a criminal investigation
Security

Microsoft is under fire for threatening a security researcher with a criminal investigation

techtost.comBy techtost.com29 May 202604 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Microsoft Is Under Fire For Threatening A Security Researcher With
Share
Facebook Twitter LinkedIn Pinterest Email

After a security researcher published a series of unpatched bugs in Microsoft products, along with code to exploit them, the company is now threatening legal action and calling the police to deal with them. Microsoft’s veiled threat rekindles a long-running argument about the responsibility, if any, of security researchers to uncover vulnerabilities affecting large and wealthy tech giants.

On Wednesday, Microsoft published a blog post criticizing the researcher, who says “Nightmare Eclipse”, for publicly revealing a number of bugs, such as BlueHammer, RedSun, UnDefendand YellowKey. The flaws affected products such as Windows Defender’s built-in antivirus engine and the BitLocker disk encryption tool.

The core of Microsoft’s complaints is that the researcher didn’t try to report the bugs so the company could fix them. That would be “responsible,” as Microsoft’s blog put it. The other side of the company’s argument is that by publishing the details of the bugs and how to exploit them before they were patched, Nightmare Eclipse may have aided malicious hackers. Some of the vulnerabilities revealed by Nightmare Eclipse have since been used by hackers in real attacks, according to Microsoft, as well as the US cybersecurity agency CISA.

“Our Digital Crimes Unit will continue to prosecute these actors and those who enable their criminal activity — coordinating as necessary with law enforcement around the world,” Microsoft wrote. (Microsoft’s Digital Crimes Unit is tasked with protecting the company through different strategies, including “civil lawsuits, technical countermeasures, criminal referrals, and public-private partnerships,” according to its website).

In one blog series Nightmare Eclipse published in the past two weeks — without providing many specific details — claimed to have been in contact with Microsoft, but the company allegedly mistreated them, including revoking their account access to the Microsoft Security Response Center, the portal where researchers can report vulnerabilities to the tech giant. The implication of Nightmare Eclipse was that they had no choice but to release the vulnerabilities publicly, which essentially meant that at that point they were zero-days, a specific term for security flaws that are unknown to the affected software manufacturer at the time they are discovered or exploited.

The researchers published the bugs in open source repositories GitHub (the property of Microsoft) and GitLab. Researchers’ accounts on these platforms have been banned.

Nightmare Eclipse and Microsoft did not respond to a request for comment.

Cybersecurity veterans warn of a chilling outcome

This public spat brings back a long-standing and still somewhat contentious debate: Do independent security researchers have a duty to ensure that the vulnerabilities they find are patched? And how far should they go to make sure that companies whose products are vulnerable actually fix them?

One part of this debate, which has been fully settled and widely acknowledged, is that researchers deserve to be paid for their work. While it may sound obvious these days, it took years of struggle, captured in part during a campaign launched in 2009 titled “No more free bugs.” Nearly 20 years later, most small and large companies pay “bug bounties,” which today can run into six figures or more, to researchers who uncover private bugs and coordinate the publication of their data once the bugs are fixed.

In response to this latest feud with Nightmare Eclipse, countless researchers have shared their bad experiences by reporting bugs to Microsoft. It’s fair to say that much of the cybersecurity community is vocally unhappy with Microsoft’s handling of this issue. That includes cybersecurity veterans like Katie Moussouris, founder of Luta Security, who while working at Microsoft in the mid-to-late 2000s pioneered bug bounties and convinced the tech giant to move away from the concept of “responsible disclosure” by framing the process as “coordinated disclosure.”

“Invoking the term ‘responsible’ disclosure was the first strike in my book,” Moussouris told TechCrunch, referring to Microsoft’s blog post. “Adding threat of prosecution by reporting [Digital Crimes Unit] was over the top and will only result in security researchers not trusting Microsoft.”

Moussouris warned that the consequences of security researchers losing trust with Microsoft could have the chilling effect of fewer people reporting bugs, “making it less secure for all of us.”

Security researcher and former Microsoft employee Kevin Beaumont he also called out Microsoft in a blog postdescribing the company’s position as a “garbage fire of its own making”.

“Proof of concept exploit creation and distribution for zero days is ‘criminal activity’ now?” Beaumont wrote. “Responsible disclosure is often framed to protect the product owner rather than the customer – using it to try to prosecute people is a new low.”

When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.

bounties bug Criminal cyber security Fire hacker investigation Microsoft researcher security threatening Zero-days
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCognition’s Scott Wu says AI coding agents shouldn’t replace humans
Next Article YouTube adds new podcast features, including an AI recommendation tool and ‘Auto Speed’
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Florida ransomware dealer convicted of helping ransomware gang extort US companies

10 July 2026

Another massive data breach exposed millions of driver’s license numbers

8 July 2026

Hacktivists call out Trump by hacking and defacing US military websites

8 July 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Phia Accused of ‘Cookie Stuffing’, Taking Affiliate Credit for Unearned Purchases

11 July 2026

Filed Under: College Fizz App Accuses VC Of Sharing Confidential Startup Info With Rival Sidechat

11 July 2026

Meta removes controversial AI feature on Instagram after backlash

11 July 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Don’t want to invest in Elon Musk? Two new ETFs expressly exclude him

10 July 2026

India’s payments chief believes artificial intelligence will play a big part in the next era of digital payments development

28 June 2026

Early Bird pricing ends tonight for the Founder Summit

26 June 2026
Startups

Phia Accused of ‘Cookie Stuffing’, Taking Affiliate Credit for Unearned Purchases

Oratomic raises $300M to build sustainable quantum computer that only needs 20,000 qubits

These AI startups are growing revenue at an ever-faster pace

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.