5/30/2026 at 12:33:59 AM
Attacking the messenger is an age-old trend in the bug reporting arena.Microsoft has the backing of many governments, and has access to the best legal teams possible, leaving this guy in a world of hurt.
Microsoft seems to have brought this on themselves by creating a complex and user-hostile bug reporting system. It seems to me that they could have offered this person a job or a contract, because Eclipse has been amazingly effective at uncovering high-severity exploits.
Also, Eclipse could have approached various governments offering the exploits for sale, because a lucrative market exists for such things, assuming they aren't already in the NSA portfolio. Lots of above-board companies do the same thing.
Quotes in this article blame Eclipse for the damage, but the blame should really rest with Microsoft. Eclipse is apparently just one person using an AI framework. Microsoft has vastly more resources to discover and fix problems with their products, but they never seem to do it themselves.
by anonymousiam
5/30/2026 at 1:10:42 AM
I knew a guy who reported an Apple 0day and got similar treatment. I would expect it from those petty bitches. Guess times change.by RajT88
5/30/2026 at 2:46:10 AM
You don't even need to find a whole 0day, you can find step 3 of 14.Just dump it anon or sell it, don't even try to claim a bounty or get a cve. Without elaborating, they will make sure you regret it
Same goes for games. If you find RCE, report it and move on. If it remains unfixed let a journalist know. Do NOT accept their invite to the studio, they want to have you arrested. Would have happened to me were it not for one dude with a conscience at the company warning me not to go
by monster_truck
5/30/2026 at 11:06:22 PM
Do you have any evidence this is actually happening to good faith security researchers?There are many examples of Microsoft and other large corporations treating security researchers well. Microsoft hosts BlueHat, where they invite external parties to talk about their findings. They thank researchers monthly who do contribute reports to MSRC. As I recall, they treated bunnie well, and I think they also treated “hoodie” (the original Xbox 360 hacker) well as well.
by lolsowrong
5/30/2026 at 2:11:48 AM
Now iOS 0-day is worth up to $2,000,000 on gray market so Apple kind a take it seriously.by SXX
5/30/2026 at 2:25:26 AM
If you find a real iOS zero day that you think has a market value of 2 million, how do you (a) find a legit buyer for it, and (b) ensure you get paid, presumably in your own choice of cryptocurrency?by walrus01
5/30/2026 at 2:36:41 AM
https://en.wikipedia.org/wiki/Market_for_zero-day_exploitsby teravor
5/30/2026 at 2:51:37 AM
Even if you dont count obvious dark markets there is plenty of well known companies mostly from Israel buying exploits.You can even reach them via Linkedin and even demonstrate and sell in person with all paperwork. No risk here because they will re-sell them for much more.
Having it both fully anonymous, safe and in crypto will be harder. You need to have a trusted friend with right connections in industry not to get scammed.
by SXX
5/30/2026 at 2:47:58 AM
Are you asking for step by step instructions?by moscoe
5/30/2026 at 2:57:15 AM
no, I'm making the rhetorical point that the sort of persons that might have 2 million laying around to pay for an iOS zero day for blackhat type purposes might not be the most honorable or likely to actually pay you. And what recourse would you have?by walrus01
5/30/2026 at 3:08:08 AM
This depends on what you consider black hat. Israeli company that sells surveillance malware to dictatorships around the globe isnt exactly moral, but its legal business.Unlike Apple or Microsoft buying and selling exploits is their only source of income so they have no motivation not to pay. Reputation is much more important. Also legal system does work in Israel.
by SXX
5/31/2026 at 7:35:21 AM
dictatorships are not there main customers. There are many, also western, governments and their agencies customers of such services.by cdud3
5/31/2026 at 9:47:09 AM
He's asking for a friendby 7bit
5/30/2026 at 5:18:51 AM
When someone says memory corruption is nothing special, they aren't the ones paying those amounts.Naturally there are other kinds of bugs as well.
However reducing 70% of root causes, saves a bunch of money already.
by pjmlp
5/30/2026 at 6:59:28 AM
I am really somehow happy about this feud as it really demasks Microsoft. The signal Microsoft sends to their costumers (also corporate and government) is IMHO as disasterous as it is to security researchers.by riedel
5/30/2026 at 5:16:21 AM
Worse is that they proud themselves of having a security culture since XP SP2, hence having even a security conference and related podcast.So something went down really bad on their side.
by pjmlp
5/30/2026 at 7:48:01 PM
Assuming he wasn't trying to extort them -- which seems absurd, this is a real self-own by Microsoft. We'll see what July 14th brings.by scamdrill