@chthonic @wdormann This is absolutely not “normal” but it does happen enough for the pattern to show itself…namely the vendor here is making ticky-tack calls to not provide a bounty. Yes, MSRC has public guidelines, but they are often too rigid, IMHO. Whatever bounties were in play, they are cheaper than all the ish that has happened, namely the brand impact to MSFT.
snowride509@infosec.exchange
@snowride509@infosec.exchange