Microsoft is threatening legal action for disclosing exploits

EDITOR BRIEF
Microsoft is under scrutiny after a person using the name Nightmare Eclipse posted proof-of-concept exploit code and criticized the company’s vulnerability handling. Security researcher Kevin Beaumont highlighted Microsoft’s response, including threats of a criminal case over lack of coordinated disclosure and disabling the person’s GitHub, GitLab, and MSRC accounts.
INSIGHTS
The dispute underscores growing tension between vendors and researchers over how quickly vulnerabilities should be disclosed when fixes are delayed or disputed. Aggressive legal threats may deter irresponsible releases, but they also risk chilling security research and damaging trust in bug reporting channels.
COMMENTS
Discussion
> geekhaus:~$ next read?


