Microsoft and security researcher Nightmare Eclipse are in a public fight over how security flaws should be handled.
Over recent weeks, Nightmare Eclipse posted working exploit code online for several serious Windows bugs before Microsoft released fixes.
The flaws affect major Windows security features like Microsoft Defender and BitLocker.
The researcher says they first reported the problems privately but claims Microsoft ignored the reports, delayed responses, and shut down their bug reporting account. They then published the details and proof-of-concept code publicly.
On May 27, Microsoft responded in a blog post, saying that releasing exploit code before patches are ready puts users at risk because attackers can immediately use it.
Microsoft also warned it would continue legal action against those enabling cybercrime like Eclipse
Nightmare Eclipse argues they went public because of slow fixes and poor treatment from Microsoft in the past.
Ahem... Cygames are the worst company I've ever had the displeasure of dealing with. I have a laundry list of reasons why. Its been going on for over two years. I genuinely wish them the worst. I refuse any and all contact with them. Some were interested of the end result.
@DevilMayCry Ya gotta give me something to buy, though. I own it all on Steam. Give me ports of DmC:DE, DMC5:SE, and the switch version of DMC3. I have money and no way to spend it on DMC stuff for myself on Steam.
@AveAutumn@gbvs_official@Cygames_EN Or somebody who hasn't done anything wrong to begin with. I've only, y'know, shown proof and answered everything. I just can't fit it all into one tweet. The support is greatly appreciated, thanks for standing up for me.