Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Insider Access Failure: Former Microsoft Engineer’s Unrevoked Privileges Lead to New Zero‑Day Disclosures

A former Microsoft employee retained privileged access for two months after termination and disclosed a new Windows Defender zero‑day. The incident underscores the importance of rapid off‑boarding and continuous privileged‑account monitoring for audit readiness.

LiveThreat™ Intelligence · 📅 September 24, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
databreachtoday.com

Insider Access Failure: Former Microsoft Engineer’s Unrevoked Privileges Lead to New Zero‑Day Disclosures

What Happened – A former Microsoft Europe employee, Abdelhamid Naceri, disclosed a new Windows Defender zero‑day (codenamed BigDiskBuster) after his termination. Court documents and internal emails show Microsoft did not revoke his access to internal systems for two months following his departure, allowing him to continue probing and releasing vulnerabilities.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of inadequate off‑boarding and privileged‑account de‑provisioning – a core control‑area that continuous‑monitoring programs are built to protect.
  • Highlights the need for auditable evidence that access revocation is performed promptly and verified, supporting a defensible audit trail.
  • Shows how insider‑threat scenarios can translate into external zero‑day exploits, impacting both product security and downstream customers.

Who Is Affected – Large‑scale software vendors, cloud service providers, and any organization that manages privileged accounts for former employees or contractors.

Recommended Actions

  • Review and automate your off‑boarding workflow to ensure immediate revocation of all privileged credentials.
  • Deploy continuous monitoring of privileged‑account activity and generate immutable logs for audit readiness.
  • Conduct a post‑mortem of the incident to update policies around employee termination and access reviews.

Technical Notes – The disclosed flaw resides in Windows Defender’s scanning engine; while no CVE number is yet assigned, the vulnerability is a remote‑code‑execution risk that could be weaponized by threat actors. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/nightmare-eclipse-reveals-name-story-behind-ms-zero-days-a-32907 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →