I can’t help but feel Microsoft will regret this.
Guy finds zero days and gets no compensation. Instead gets banned.
Guy sells zero days elsewhere.
Not to mention all the other people who find 0-days. Reputation matters a lot.
Why would they regret it? According to the person who found them, they put those vulnerabilities there for a reason.
> Guy sells zero days elsewhere.
No problem. The CIA will give it's high level officers millions of dollars in gold bars simply for the asking. I'm sure purchasing exploits doesn't even require a purchase order.
But the story is supposedly about him posting the zero-day exploits, not selling them. It’s in the title.
He also got banned from Gitlab, which isn’t related to Microsoft at all.