Get tomorrow's brief in your inbox
Today: AT&T sues California regulators to eliminate affordability oversight and Carrier of Last Resort obligations, seeking federal preemption from the Trump FCC. Microsoft reverses course after security community backlash, stating it will not pursue legal action against researchers disclosing vulnerabilities. The developments highlight tensions between corporate interests and public oversight in both telecommunications infrastructure and vulnerability disclosure practices.
AT&T Sues California Regulators For Trying To Make Broadband Affordable
AT&T filed suit against the California Public Utilities Commission (CPUC) seeking to eliminate state oversight over its retirement of copper telephone infrastructure and asking the Trump FCC to preempt California's regulatory authority. The lawsuit stems from CPUC's 2024 decision requiring AT&T to upgrade failing copper networks to fiber rather than leaving customers without service or forcing them to more expensive wireless alternatives. AT&T has successfully eliminated Carrier of Last Resort obligations in 20 of 21 states where it operates, with California standing as the sole holdout requiring the company to maintain service to all potential customers in its territory. The legal action targets not just copper retirement rules but California's broader affordability requirements, public safety conditions, and merger oversight that AT&T characterizes as outdated regulatory obstacles blocking modernization.
Microsoft says it will not pursue security researchers after zero-day backlash
Microsoft reversed its position on vulnerability disclosure after a company blog post threatened legal action against researchers publishing uncoordinated zero-day disclosures. The original post condemned recent Windows zero-day releases by researcher Nightmare Eclipse as never justifiable and warned that Microsoft's Digital Crimes Unit would continue bringing cases against those enabling criminal actors. Following widespread criticism from the security community, Microsoft issued a clarification stating it has no intention to pursue action against individuals conducting or publishing security research. The company acknowledged failures in researcher relationships and dropped use of the term "responsible disclosure" in favor of Coordinated Vulnerability Disclosure. Microsoft included the caveat that it will work with law enforcement when individuals break the law and engage in malicious activity causing real harm to customers. The controversy emerged after Nightmare Eclipse alleged Microsoft deleted their Security Response Center account, withheld bounty payments, and removed attribution from advisories.
Telecommunications providers in California: Review infrastructure retirement plans against CPUC requirements requiring fiber upgrades rather than wireless substitution. Monitor AT&T v. CPUC litigation for changes to state regulatory authority and federal preemption of affordability requirements.
Vulnerability disclosure programs: Audit program communications and researcher-facing documentation for threatening language or terms like "responsible disclosure" that could damage security community relationships. Implement documented procedures for bounty processing, attribution tracking, and account management.
Security research participants: Document all interactions with vendor vulnerability programs including submission dates, communications, bounty status, and attribution agreements. Microsoft's reversal demonstrates that public documentation and community support can counter vendor legal threats.
Organizations with California operations: Track the AT&T litigation for broader implications beyond telecommunications. CPUC affordability requirements and merger conditions affect multiple sectors. Federal preemption could eliminate state-level consumer protections across regulated industries.