news.mlab.sh
Back to the feed
threat-intel

Microsoft says it will not pursue security researchers after zero-day backlash

Medium
Summary

Microsoft retracted a controversial blog post condemning security researchers who disclose zero-day vulnerabilities, stating it has no intention to pursue legal action against them. The initial statement, perceived as a threat, sparked significant backlash from the security community over allegations of improper handling of researcher relationships. Microsoft is now emphasizing a commitment to constructive collaboration and a revised approach to vulnerability disclosure.

Following a public outcry, Microsoft has reversed its stance on pursuing security researchers who responsibly disclose zero-day vulnerabilities. The initial blog post, which criticized uncoordinated Windows zero-day releases and threatened legal action against researchers, was widely interpreted as a deterrent to independent security research. This shift in policy reflects a recognition of the crucial role security researchers play in identifying and mitigating vulnerabilities, and a desire to foster a more collaborative relationship. Microsoft acknowledged internal failures in its interactions with researchers, including allegations of account deletion and withheld bounty payments, and is now prioritizing a more respectful and professional engagement.

Read the full article at The Record