Microsoft wins 'lamest vendor' at Pwnie Awards 2026 for threatening security researchers with legal action
Microsoft has won the "lamest vendor response" category at the Pwnie Awards 2026, the annual award show at Def Con that acknowledges the best and worst in cybersecurity over the past year.
The technology giant won the award for publishing a May blog post that threatened security researchers with legal action if they publish zero-days about its products. Microsoft published the blog post following a stream of public reports by a security researcher called “Nightmare Eclipse,” who publicly released details about several zero-day vulnerabilities in Microsoft's software, which were unknown to the company at the time they were published. The company allegedly ignored the researcher's privately submitted reports.
Microsoft's blog post drew widespread criticism, in part because security researchers still get threatened a lot for their work. Microsoft eventually backtracked, but clearly not sufficiently enough to regain the trust it lost from the security community, as evidenced by this award.
"This is a shame award. Don't forget to feel that shame," one of the hosts reminded the crowd. The Pwnie Awards said nobody from Microsoft showed up to accept the honor.
I reached out to Microsoft to see if it had any comment, or if it plans to accept the award, but haven't yet heard back.
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent blogs include: When AI chatbots and LLMs get legal, check your privilege | Most fitness wearables lack end-to-end encryption and don't disclose government data demands | U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents | Why ad blockers are a top security and privacy defense for everyone | A beginner's guide to analyzing the network traffic of apps and websites
Relatedly: Meta won the "epic fail" Pwnie Award, thanks to the discovery of a really easy-to-abuse security vulnerability in its Meta AI chatbot, which hackers exploited to take over at least 20,000 people's Instagram accounts.
The bug allowed anyone to ask the AI-powered chatbot to send a password reset email to a different email address on file than what was registered with the account holder. By sending a password reset to an attacker-controlled email address, the attacker could take over the entire account.
Nobody from Meta turned up to accept this award, either, and a spokesperson did not respond to my email asking if they would accept the award.
Thank you so much for reading ~this week in security~! I hope you enjoyed and found this article helpful. If you like it, please share a link on your social media! Please email me with any feedback, questions, or comments about this article: this@weekinsecurity.com.