Microsoft Swaps Bug Bounties for Legal Threats in Disastrous Clash with Security Researcher
Microsoft is currently threatening legal action against a security researcher operating under the handle Nightmare Eclipse following the public disclosure of several software exploits. The conflict arises from the researcher's decision to bypass private disclosure channels and bug bounty programs, opting instead to release vulnerability details directly to the public. While Microsoft maintains that such actions jeopardize user safety by providing attackers with ready-made tools, the decision to pursue legal recourse has sparked significant debate within the cybersecurity industry regarding the ethics of coordinated disclosure versus public transparency.