Microsoft wouldn't look at a bug report without a video. Researcher maliciously complied
ID: 5fc0fd01-701a-56ea-8ee2-fdaed8e2efab
STIX ID: report--5fc0fd01-701a-56ea-8ee2-fdaed8e2efab
Feed Name: The Register (Security)
Vulnerability analyst Will Dormann criticized Microsoft’s Security Response Center for refusing to review his vulnerability reports without a video proof-of-concept, prompting him to submit a satirical 15-minute video after already providing screenshots and clear steps. The piece contrasts MSRC’s request with common practices at CISA VINCE and the UK NCSC, which typically don’t mandate videos, while Microsoft maintains that additional evidence can help assessment and bug bounty decisions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
