Microsoft's stance on zero-day exploits criticized for inconsistency on vulnerability disclosure (doublepulsar.com)
0xBASE INTEL BRIEF
- Nightmare Eclipse publicly disclosed multiple zero-day exploits including a BitLocker bypass
- Microsoft called the disclosure 'criminal activity' in a MSRC blog post
- Beaumont highlights Microsoft's inconsistent history with exploit hosting and hiring
"Kevin Beaumont criticizes Microsoft's response to researcher Nightmare Eclipse, who publicly disclosed zero-day exploits including a BitLocker bypass. Microsoft's MSRC blog called such disclosure 'criminal activity'. Beaumont highlights contradictions: Microsoft hosts exploits on GitHub and previously hired a researcher who did the same. He warns that criminalizing disclosure weakens cybersecurity."
no comments yet.