Skip to main content
See every side of every news story
Published loading...Updated

Windows BitLocker exploit sparks messy feud between Microsoft and the researcher who exposed it

Microsoft said the researcher published exploit code before patches were available, while attackers have since used some flaws in real-world attacks, officials said.

  • On Wednesday, Microsoft published a blog post criticizing security researcher Nightmare Eclipse for publicly disclosing unpatched vulnerabilities in Windows Defender and BitLocker, while threatening legal action through its Digital Crimes Unit.
  • Nightmare Eclipse claims Microsoft revoked access to its Microsoft Security Response Center after the researcher contacted the company, then published exploit code on GitHub and GitLab without receiving a patch.
  • Katie Moussouris, founder of Luta Security, told TechCrunch that invoking "responsible disclosure" was "the first strike," warning that threatening prosecution will only result in researchers distrusting Microsoft.
  • Security researcher Kevin Beaumont called Microsoft's position "a dumpster fire of its own making," while industry consensus favors "coordinated disclosure," where companies patch vulnerabilities before public release.
  • Anthropic's Project Glasswing found 10,000 critical vulnerabilities in one month, with only 97 patched, illustrating how alienating researchers widens the gap between discovery and remediation across the industry.
Insights by Ground AI

13 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources lean Left
67% Left

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

GIGAZINE broke the news on Friday, May 29, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal