SAN FRANCISCO — Microsoft published a blog post criticizing security researcher Nightmare Eclipse for publicly disclosing unpatched vulnerabilities in Microsoft products. The company stated that Nightmare Eclipse did not attempt to report the bugs through proper channels before releasing technical details online.

The disclosed vulnerabilities, named BlueHammer, RedSun, UnDefend, and YellowKey, affected Microsoft products including the Windows Defender antivirus engine and the BitLocker disk-encryption tool. Microsoft said some of these vulnerabilities have already been exploited in real-world attacks. The U.S. cybersecurity agency CISA separately confirmed that the flaws have been used by hackers.

Nightmare Eclipse published the vulnerabilities on the open-source platforms GitHub and GitLab. Both platforms subsequently banned the researcher’s accounts. Nightmare Eclipse claimed in prior blog posts to have been in contact with Microsoft before the disclosure and alleged that Microsoft mistreated them, including by revoking access to their Microsoft Security Response Center account.

Microsoft’s blog post said its Digital Crimes Unit would continue pursuing cases against actors and those who enable criminal activity, coordinating with law enforcement globally. According to its website, the unit employs civil legal actions, technical countermeasures, criminal referrals, and public-private partnerships.

Security experts criticized Microsoft’s response. Katie Moussouris, founder of Luta Security and a former Microsoft employee who pioneered bug bounties in the mid- to late 2000s, said, “Invoking the term ‘responsible’ disclosure was the first strike in my book.” She added, “Adding a threat of prosecution by mentioning [Digital Crimes Unit] was over the top, and will only result in security researchers distrusting Microsoft.” Moussouris warned that declining trust could lead to fewer vulnerability reports, making systems less safe for everyone.

Kevin Beaumont, a security researcher and former Microsoft employee, described Microsoft's position as a “dumpster fire of its own making.” He wrote, “Proof of concept exploit creation and distribution for zero days is ‘criminal activity’ now?” Microsoft and Nightmare Eclipse did not respond to requests for comment.