Tech

Microsoft under fire for threatening security researcher with criminal investigation

Noozly Editorial Desk ·
Microsoft under fire for threatening security researcher with criminal investigation

Microsoft has drawn sharp criticism from parts of the cybersecurity community after publicly rebuking an independent researcher who exposed a string of flaws in some of its most widely used security software, reigniting a long-simmering argument over how vulnerability disclosures should be handled.

The company posted a blog entry on Wednesday singling out a researcher operating under the alias "Nightmare Eclipse," who had gone public with details on four separate vulnerabilities nicknamed BlueHammer, RedSun, UnDefend, and YellowKey. According to Microsoft, the flaws touched core protective tools built into Windows, including the operating system's native antivirus engine, Defender, and its full-disk encryption feature, BitLocker.

Rather than simply detailing the technical fixes, Microsoft's post framed the disclosures within the context of ongoing legal enforcement. The company stated that its internal Digital Crimes Unit intends to keep pursuing legal action against individuals it considers responsible for this kind of activity, as well as anyone who assists them, working alongside police agencies internationally when necessary.

That unit is not new — Microsoft describes it on its own site as a mechanism for defending the company through a mix of tactics, ranging from lawsuits and referrals to criminal authorities to technical disruption efforts and joint initiatives with outside partners. Historically, the group has focused on botnets, phishing networks, and organized cybercrime operations, which is part of why critics say applying that same framing to a solo bug hunter feels disproportionate.

Compounding the researcher's situation, the accounts used to publish the vulnerability write-ups were subsequently suspended on two major code-hosting platforms: GitHub, which Microsoft itself owns, and the rival service GitLab. Losing access to both effectively erased the public record the researcher had built and cut off a channel commonly used by security professionals to share proof-of-concept details.

The episode has revived a decades-old tension in the security field between "full disclosure," where flaws are published openly so users and defenders can react quickly, and "coordinated disclosure," where researchers wait for a vendor to ship a patch before going public. Independent researchers frequently argue that going public applies pressure on large vendors that might otherwise sit on bug reports for months; vendors counter that premature disclosure can hand attackers a roadmap before defenses are ready. By invoking language typically reserved for criminal actors, Microsoft's response has struck many in the field as an attempt to discourage that kind of public pressure altogether, rather than a genuine child-safety or fraud concern.

Neither Microsoft nor the researcher has indicated how the dispute might be resolved, and it remains unclear whether the banned accounts will be reinstated or whether any formal legal referral will follow. The incident is likely to fuel continued scrutiny of how major software vendors treat outside researchers who find holes in flagship products, particularly when those products — like Defender and BitLocker — are relied upon by hundreds of millions of everyday users for basic protection against malware and data theft.

Source: TechCrunch

technologyinnovationdigitalmicrosoftfirethreatening
Original source
TechCrunch →

Related articles

Fidji Simo steps down from OpenAI’s no. 2 role
Tech

Fidji Simo steps down from OpenAI’s no. 2 role

OpenAI's No. 2 executive, Fidji Simo, is stepping down from her full-time role after her medical leave proved longer than expected — a leadership vacuum that comes at a tricky time as the company eyes a possible IPO and races to catch Anthropic in the enterprise market.