
Microsoft is threatening legal action and a criminal investigation against a security researcher using the handle Nightmare Eclipse after the researcher publicly posted several unpatched vulnerabilities in Microsoft products along with exploit code. Microsoft says the disclosures endanger customers and has signaled it may involve law enforcement; the researcher and parts of the security community argue public postings can spur fixes and expose flaws that vendors should patch. Additional coverage notes the company's confrontational language has alarmed commentators who fear such threats could chill necessary research. The dispute has reignited a broader debate over who is responsible for finding and disclosing software flaws.
Click a connection line between nodes to view confidence and evidence.