Microsoft Threatens Legal Action Against Security Researcher
Microsoft has threatened a security researcher with criminal prosecution over the public disclosure of unpatched vulnerabilities in Windows Defender and BitLocker. The cybersecurity community has expressed outrage in response.
Background
A researcher known as "Nightmare Eclipse" disclosed several vulnerabilities, named BlueHammer, RedSun, UnDefend, and YellowKey, on GitHub and GitLab. Microsoft claims that the researcher should have reported these bugs privately before publishing exploit code, arguing for "responsible disclosure."
The Researcher’s Perspective
The researcher alleges that Microsoft revoked their vulnerability reporting account, leaving them with no choice but to publicly disclose the vulnerabilities. Both GitHub and GitLab accounts belonging to the researcher have since been banned.
Community Response
Cybersecurity veterans have criticized Microsoft’s approach, calling it a "chilling effect" that could discourage future bug reports. Katie Moussouris, founder of Luta Security, stated that Microsoft’s use of inflammatory language and threats of prosecution is excessive and may damage trust with security researchers. She warns that fewer reported bugs will ultimately make digital systems less secure.
Kevin Beaumont, another security researcher, described Microsoft’s position as a "dumpster fire," highlighting the potential for real-world attacks on these vulnerabilities since they have been exploited in the wild.