This is not about that. This is about a security researcher that wasn't paid by Microsoft's bug bounty program when they found a security bug.
Bug bounty programs exist to prevent this exact scenario. To give people a reward for privately disclosing the vulnerability with the devs instead of publicly/to a bad actor.