discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Microsoft under fire for threatening security researcher with criminal investigation

Microsoft criticized a researcher for publicizing unpatched bugs and warned of legal action, triggering backlash from cybersecurity veterans.

By Lorenzo Franceschi-Bicchierai·May 29·techcrunch.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Microsoft under fire for threatening security researcher with criminal investigation
Image: techcrunch.com

Microsoft is facing backlash after saying a researcher who published unpatched bugs in its products may have aided hackers and could face legal trouble. Security veterans say the company’s response could scare researchers away from reporting flaws.

Why it matters

This matters because Microsoft’s software is widely used, and how it treats vulnerability researchers affects whether people report bugs privately or go public. If researchers lose trust, more flaws may stay hidden or be exploited longer.

Microsoft found itself in a fight with a person who spots computer problems. Those problems were like hidden broken locks in software, and the person posted how they worked before Microsoft fixed them.

Microsoft says that is dangerous, because bad actors could use the same information to break into computers. The company also said it may take legal steps, which upset many people who hunt for security bugs.

Other experts think Microsoft went too far. They worry that if people who find bugs get scared, they may stop sharing warnings. That would be like removing the neighborhood lookout after they point out the broken windows.

Analysis

What happened

Microsoft published a blog post criticizing a security researcher who uses the handle “Nightmare Eclipse” after the researcher disclosed a set of unpatched bugs and shared exploit code. The flaws were said to affect Microsoft products including the Windows Defender antivirus engine and BitLocker, the company’s disk-encryption tool.

Microsoft’s main complaint is that the researcher did not go through the company’s normal reporting path first. In Microsoft’s view, that would have been the “responsible” route because it would have given the company time to fix the issues before details were made public. Microsoft also argued that publishing exploit details before patches were available may have helped malicious hackers. The company said some of the flaws have since been used in real-world attacks, citing its own view and the U.S. cybersecurity agency CISA.

The researcher’s side

Nightmare Eclipse has said in recent posts that they were in contact with Microsoft, but that the company treated them badly. They alleged that Microsoft revoked their MSRC account, which is the portal researchers use to report bugs. The researcher then published the vulnerabilities on GitHub and GitLab. Those accounts were later banned.

Why the reaction is so strong

The episode revived an old argument in security: how much responsibility researchers have to privately coordinate disclosures before sharing technical details. Many people in the field agree researchers should be paid and credited for finding bugs, but they also worry about public exploit code appearing before fixes are ready.

Still, the backlash here is about Microsoft’s tone and threat of escalation. Katie Moussouris, who helped shape modern bug bounty practices at Microsoft, said the company’s language around “responsible” disclosure was a mistake and that mentioning its Digital Crimes Unit created a threat of prosecution. Kevin Beaumont also criticized Microsoft’s stance and warned that treating proof-of-concept exploit work as criminal activity could discourage researchers from reporting flaws at all. The broader concern is a chilling effect: if researchers stop trusting Microsoft, fewer bugs may be reported, and users could end up less safe.

Key points

  • Microsoft criticized Nightmare Eclipse for publishing unpatched bugs and exploit code.
  • The company said the flaws affected products such as Defender and BitLocker.
  • Nightmare Eclipse claimed Microsoft mistreated them and revoked access to its reporting portal.
  • Security veterans warned that legal threats could discourage future vulnerability reports.
  • The dispute has reignited debate over coordinated disclosure and researcher trust.

Originally reported at

techcrunch.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityethicsresearchtechpolicy

Author

Lorenzo Franceschi-Bicchierai

Intelligence analysis by

GPT-5.4 Mini

Published

May 29, 2026

Source

techcrunch.com

Share

Topics

securityethicsresearchtechpolicy

Related

More from this desk

Jul 29·engadget.com

Pokémon Pokopia's First DLC Comes To Switch 2 On August 5

Pokémon Pokopia's first DLC, Bubbly Basin, arrives on August 5, introducing an underwater area to explore and a new Dive move. The update is part of the Pokémon Pokopia Expansion Pass, which costs $35.

Jul 29·9to5google.com

Galaxy Z Fold 8 gives apps new scaling options for its large displays

Samsung's Galaxy Z Fold 8 gets a new feature in One UI 9 that allows users to adjust the zoom level of individual apps on the large display. This feature is currently in beta and can be enabled in Samsung Labs.

Jul 29·techcrunch.com

Elon Musk’s X settles multiyear legal battle with the World Federation of Advertisers

Elon Musk's X has settled its multiyear legal battle with advertising trade group the World Federation of Advertisers (WFA). The settlement ends Musk's aggressive attempt to hold advertisers legally responsible for pulling spending from X over brand safety concerns.

Jul 29·9to5google.com

Samsung has restocked Galaxy Z Fold 8’s popular ‘Pistachio’ color, shipping in August

Samsung has restocked the Galaxy Z Fold 8 in the popular 'Pistachio' color, with shipping dates moved up to August. The device was previously delayed due to a sell-out and shipping issues.