Microsoft under fire for threatening security researcher with criminal investigation
Microsoft criticized a researcher for publicizing unpatched bugs and warned of legal action, triggering backlash from cybersecurity veterans.
Intelligence analysis by GPT-5.4 Mini

Microsoft is facing backlash after saying a researcher who published unpatched bugs in its products may have aided hackers and could face legal trouble. Security veterans say the company’s response could scare researchers away from reporting flaws.
Microsoft found itself in a fight with a person who spots computer problems. Those problems were like hidden broken locks in software, and the person posted how they worked before Microsoft fixed them.
Microsoft says that is dangerous, because bad actors could use the same information to break into computers. The company also said it may take legal steps, which upset many people who hunt for security bugs.
Other experts think Microsoft went too far. They worry that if people who find bugs get scared, they may stop sharing warnings. That would be like removing the neighborhood lookout after they point out the broken windows.
Analysis
What happened
Microsoft published a blog post criticizing a security researcher who uses the handle “Nightmare Eclipse” after the researcher disclosed a set of unpatched bugs and shared exploit code. The flaws were said to affect Microsoft products including the Windows Defender antivirus engine and BitLocker, the company’s disk-encryption tool.
Microsoft’s main complaint is that the researcher did not go through the company’s normal reporting path first. In Microsoft’s view, that would have been the “responsible” route because it would have given the company time to fix the issues before details were made public. Microsoft also argued that publishing exploit details before patches were available may have helped malicious hackers. The company said some of the flaws have since been used in real-world attacks, citing its own view and the U.S. cybersecurity agency CISA.
The researcher’s side
Nightmare Eclipse has said in recent posts that they were in contact with Microsoft, but that the company treated them badly. They alleged that Microsoft revoked their MSRC account, which is the portal researchers use to report bugs. The researcher then published the vulnerabilities on GitHub and GitLab. Those accounts were later banned.
Why the reaction is so strong
The episode revived an old argument in security: how much responsibility researchers have to privately coordinate disclosures before sharing technical details. Many people in the field agree researchers should be paid and credited for finding bugs, but they also worry about public exploit code appearing before fixes are ready.
Still, the backlash here is about Microsoft’s tone and threat of escalation. Katie Moussouris, who helped shape modern bug bounty practices at Microsoft, said the company’s language around “responsible” disclosure was a mistake and that mentioning its Digital Crimes Unit created a threat of prosecution. Kevin Beaumont also criticized Microsoft’s stance and warned that treating proof-of-concept exploit work as criminal activity could discourage researchers from reporting flaws at all. The broader concern is a chilling effect: if researchers stop trusting Microsoft, fewer bugs may be reported, and users could end up less safe.
Key points
- Microsoft criticized Nightmare Eclipse for publishing unpatched bugs and exploit code.
- The company said the flaws affected products such as Defender and BitLocker.
- Nightmare Eclipse claimed Microsoft mistreated them and revoked access to its reporting portal.
- Security veterans warned that legal threats could discourage future vulnerability reports.
- The dispute has reignited debate over coordinated disclosure and researcher trust.



