Tech giant Microsoft has threatened independent security researcher “Nightmare Eclipse” with civil legal action and criminal referrals this week after they publicly disclosed a series of unpatched zero-day vulnerabilities affecting Windows systems.
On Wednesday, the Redmond-based corporation published a blog post targeting the researcher for releasing the technical details of critical flaws, including BlueHammer, RedSun, UnDefend, and YellowKey. These security vulnerabilities directly impact core Windows components, such as the built-in antivirus engine, Microsoft Defender, and the drive-encryption software, BitLocker.
Microsoft’s primary grievance centres on the researcher’s decision to bypass the standard vulnerability reporting process, an action the tech giant deemed irresponsible. By publishing functional exploit code before patches were developed, Microsoft argues that Nightmare Eclipse actively assisted cyber criminals. Both Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) have confirmed that malicious actors are already exploiting some of these newly exposed vulnerabilities in active campaigns.
“Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity — coordinating as needed with law enforcement around the world,” Microsoft wrote. The company’s Digital Crimes Unit is tasked with protecting the ecosystem through civil litigation, technical countermeasures, and criminal referrals, according to its website.
The Researcher’s Defence: A Broken Reporting System
However, the narrative is not entirely one-sided. In a series of blogs published over the past fortnight, Nightmare Eclipse claimed they attempted to engage with Microsoft but faced mistreatment. The researcher alleged that Microsoft revoked their access to the Microsoft Security Response Center (MSRC) portal—the official channel for reporting security flaws. Consequently, Nightmare Eclipse argued they had no viable alternative but to release the bugs publicly as zero-days.
The proof-of-concept exploits were initially hosted on open-source repositories GitHub (which is owned by Microsoft) and GitLab. Both platforms have since terminated the researcher’s accounts.
Nightmare Eclipse declined to comment on the situation, while Microsoft has refused to provide further statements beyond its published blog post.
Cybersecurity Experts Warn of a Chilling Effect
This escalation has reignited a fierce, long-standing debate within the information security sector: do independent researchers owe a duty of care to multi-billion-pound technology corporations? Furthermore, to what lengths should researchers go to ensure a vendor resolves a security flaw?
From ‘No More Free Bugs’ to Co-ordinated Disclosure
While the industry now widely accepts that security researchers should be compensated for their discoveries—a shift driven by the “No More Free Bugs” campaign in 2009—the reporting process itself remains highly contentious. Today, most major technology firms operate bug bounty programmes, offering substantial financial rewards for private disclosures.
The cybersecurity community has reacted with widespread anger to Microsoft’s aggressive stance, with countless researchers sharing their own negative experiences of dealing with the company’s vulnerability reporting pipeline. Katie Moussouris, founder of Luta Security and a pioneer who helped establish Microsoft’s first bug bounty programmes, criticised the company’s choice of words. Moussouris noted that framing the issue around “responsible” disclosure rather than “coordinated disclosure” was a step backwards.
“Invoking the term ‘responsible’ disclosure was the first strike in my book,” Moussouris told TechCrunch. “Adding a threat of prosecution by mentioning [Digital Crimes Unit] was over the top, and will only result in security researchers distrusting Microsoft.”
Moussouris warned that alienating the security community could trigger a chilling effect, discouraging researchers from reporting future vulnerabilities and ultimately leaving global software users less secure.
Kevin Beaumont, a prominent security researcher and former Microsoft employee, also called out Microsoft in a blog post, describing the tech giant’s strategy as a “dumpster fire of its own making.”
“Proof of concept exploit creation and distribution for zero days is ‘criminal activity’ now?” wrote Beaumont. “Responsible disclosure quite often is framed to protect the product owner, not the customer — using it to try to criminally prosecute people is a new low.”
