Microsoft Threatens Researcher Over Bug Reports, Triggers Cybersecurity Uproar | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The cybersecurity community is blasting Microsoft for threatening legal action against a disgruntled researcher who’s been exposing Windows vulnerabilities outside the company’s normal disclosure process. 

The controversy deals with a researcher known as “Nightmare Eclipse,” who has published six unpatched “zero-day” flaws in recent weeks. This includes a proof-of-concept exploit for a Windows vulnerability known as BlueHammer that can allow an attacker to escalate their privileges to the administrator level. 

Researchers normally submit such findings to the Microsoft Security Response Center (MSRC) for patching to prevent hackers from exploiting them. But Nightmare Eclipse has deliberately ignored the responsible disclosure route, citing claims that Microsoft mistreated them. 

“They mopped the floor with me and pulled every childish game they could,” the researcher wrote last month, without elaborating. “It was soo bad at some point I was wondering if I was dealing with a massive corporation or someone who is just having fun seeing me suffer but it seems to be a collective decision.”

The tension only escalated after Nightmare Eclipse disclosed more flaws this month, writing: “Microsoft has chosen to make this worst instead of resolving the situation like adults, they pulled every childish game possible.”

On Wednesday, the software giant responded with its own blog post that reiterated the need for responsible disclosure to prevent hackers from abusing such flaws and contained a legal threat.  

“Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences,” the company wrote, later adding: “Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity – coordinating as needed with law enforcement around the world.” 

Microsoft goes on to say “any disclosure outside proper coordination” could harm its customers. But that last part about pursuing potential charges against Nightmare Eclipse has sparked an uproar in the cybersecurity community since one could argue the researcher is doing Microsoft a service by exposing critical bugs. 

“Microsoft will do anything to stop people posting zero-days except fix MSRC,” tweeted Zack Korman, CTO of cybersecurity provider Pistachio. Other researchers are sharing their stories of reporting a flaw to Microsoft, but the company refusing to pay a reward or officially fixing the problem and quietly issuing a patch later.

“MSRC strung me along for a few extra months to keep me quiet, then broke their word….The interaction left such a bad taste in my mouth that I don’t really feel like interacting with them again,” wrote Gabriel Landau, a cybersecurity researcher and developer of anti-malware programs for Windows.

Nvidia support engineer Eric Warnke also wrote of Microsoft: “You cannot compel independent security researchers. You can only make it more or less attractive to work with you. Microsoft made it less attractive, and now they’re writing blog posts about shared responsibility. That’s a CYA, not a bug program designed to encourage reporting.” 

Recommended by Our Editors

Kevin Beaumont, a security researcher who previously worked at Microsoft, is also doubtful that Remond could successfully sue anyone for violating a company’s responsible disclosure policy, which is often set by the company itself.   

“If Microsoft’s tactic is to try to criminalize not following often arbitrary ‘responsible disclosure’ frameworks, good luck defending that in court — because there’s a whole clown car of prior decision making within Microsoft and facts which would emerge in that process,” he wrote noting that the Microsoft-owned Github often hosts software exploits and hacking techniques, but doesn’t necessarily remove them.  

“Microsoft should be concentrating on making better, more secure products that one person can’t run rings around,” he added. 

In the meantime, both the GitHub and GitLab pages for Nightmare Eclipse have been taken down, along with their MSRC account, preventing them from properly disclosing future bugs to Microsoft. However, the researcher has threatened to publish a  new vulnerability on July 14, warning: “I will make sure your bones are shattered that day.”

About Our Expert



——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW