Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures

Summary

A security researcher has leaked exploits for several Microsoft vulnerabilities, citing dissatisfaction with the company's vulnerability disclosure process. This action follows a similar incident involving another researcher who previously leaked Microsoft exploits due to perceived inadequate handling of security reports.

IFF Assessment

FOE

The public release of unpatched exploits provides tools for attackers, increasing the risk to defenders.

Defender Context

This highlights a growing trend of bug hunters bypassing responsible disclosure programs to publicly release exploits, potentially due to frustration with vendor response times or compensation. Defenders should be vigilant for exploits targeting Microsoft products and prioritize patching, as attackers may leverage these publicly leaked tools.

Read Full Story →