Microsoft is facing criticism over how it is handling publicly disclosed zero-day exploits, after a security researcher using the name Nightmare Eclipse began posting proof-of-concept exploit code online.

Some of the posts suggest the person may be a disgruntled former Microsoft employee, but the bigger concern for cybersecurity researcher Kevin Beaumont is how Microsoft has responded to the situation.

According to Beaumont, Microsoft has suggested it may pursue a criminal case against Nightmare Eclipse for not following what it describes as proper coordination when disclosing vulnerabilities. The company also reportedly disabled Nightmare Eclipse’s GitHub, GitLab, and Microsoft Security Response Center accounts. Beaumont argued that this makes responsible reporting harder, since a researcher cannot easily report future vulnerabilities after being banned from the main channels used for disclosure.

The dispute has raised questions about consistency in Microsoft’s approach to vulnerability disclosure. Beaumont pointed out that Microsoft has previously hired people who publicly released zero-day exploits and has also employed individuals with criminal hacking convictions. He also noted that Microsoft has bought exploits from brokers in the past.

Beaumont said Microsoft could face a difficult challenge if it tries to criminalize researchers for not following disclosure rules that are often seen as unclear or inconsistent. He argued that such a legal fight could bring more attention to Microsoft’s own past decisions around exploit research, hiring, and vulnerability handling.


Buy ExpressVPN with PayPal or Credit Card
Advertisement
READ
Russian Hackers Used Zero-Click Zimbra Email Flaw to Spy on Government and Defense Organizations