Security researcher Kevin Beaumont criticizes Microsoft's characterization of zero-day exploit publication as 'criminal activity,' arguing it misuses GitHub ownership to suppress vulnerability disclosures for its own products while allowing the same for competitors. He highlights the hypocrisy given Microsoft's history of hiring researchers who publicly released zero-days, purchasing exploits from brokers, and employing people who discussed selling exploits to adversarial nations. Beaumont warns that criminalizing responsible disclosure failures would harm the broader security community and prioritize corporate interests over collective cyber defense.

4m read timeFrom doublepulsar.com
Post cover image
Table of contents
A shared responsibility: Protecting customers through Coordinated Vulnerability DisclosureGet Kevin Beaumont’s stories in your inboxSome history

Sort: