Microsoft publishes a blog post criticizing a security researcher known as “Nightmare Eclipse” for publicly disclosing multiple unpatched vulnerabilities affecting Windows Defender and BitLocker. Microsoft says the researcher released details and exploit code without first reporting the issues to Microsoft through its vulnerability disclosure process, arguing this was not “responsible” and could help malicious attackers before patches are available. Microsoft also states that some of the disclosed vulnerabilities have been used in real-world attacks, citing both Microsoft’s assessment and remarks from the U.S. cybersecurity agency CISA.

In response to the researcher’s disclosures, Microsoft says it invoked its Digital Crimes Unit, which handles criminal referrals and coordination with law enforcement. The researcher had previously said they were in contact with Microsoft, and Microsoft’s actions allegedly included revoking access to the researcher’s Microsoft Security Response Center account, the portal used for reporting vulnerabilities. The vulnerabilities were published on public platforms, including open source repositories on GitHub and GitLab. The cybersecurity community reacts with criticism and concern about whether reporting channels are being used fairly.