Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Insider Access Failure: Former Microsoft Engineer’s Unrevoked Privileges Lead to New Zero‑Day Disclosures

A former Microsoft employee retained privileged access for two months after termination and disclosed a new Windows Defender zero‑day. The incident underscores the importance of rapid off‑boarding and continuous privileged‑account monitoring for audit readiness.

Verisq™ Intelligence · 📅 September 24, 2026 · 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
databreachtoday.com

Insider Access Failure: Former Microsoft Engineer’s Unrevoked Privileges Lead to New Zero‑Day Disclosures

What Happened – A former Microsoft Europe employee, Abdelhamid Naceri, disclosed a new Windows Defender zero‑day (codenamed BigDiskBuster) after his termination. Court documents and internal emails show Microsoft did not revoke his access to internal systems for two months following his departure, allowing him to continue probing and releasing vulnerabilities.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of inadequate off‑boarding and privileged‑account de‑provisioning – a core control‑area that continuous‑monitoring programs are built to protect.
  • Highlights the need for auditable evidence that access revocation is performed promptly and verified, supporting a defensible audit trail.
  • Shows how insider‑threat scenarios can translate into external zero‑day exploits, impacting both product security and downstream customers.

Who Is Affected – Large‑scale software vendors, cloud service providers, and any organization that manages privileged accounts for former employees or contractors.

Recommended Actions

  • Review and automate your off‑boarding workflow to ensure immediate revocation of all privileged credentials.
  • Deploy continuous monitoring of privileged‑account activity and generate immutable logs for audit readiness.
  • Conduct a post‑mortem of the incident to update policies around employee termination and access reviews.

Technical Notes – The disclosed flaw resides in Windows Defender’s scanning engine; while no CVE number is yet assigned, the vulnerability is a remote‑code‑execution risk that could be weaponized by threat actors. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/nightmare-eclipse-reveals-name-story-behind-ms-zero-days-a-32907 ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →