Microsoft GitHub Removes Security Researcher Account After Zero-Day Disclosure
TL;DR. Microsoft GitHub deactivated a security researcher's account after their public revelation of a zero-day vulnerability found within GitHub Actions, sparking debate. - The researcher publicly disclosed a zero-day vulnerability in GitHub Actions. - Microsoft GitHub subsequently removed the researcher's account. - This action followed the vulnerability's public disclosure.
- The researcher discovered and reported a supply chain vulnerability affecting GitHub Actions, allowing unauthorized repository code execution.
- Microsoft revoked access to the researcher's GitHub account and suspended their GitHub Sponsors payouts after the public disclosure.
- The removed GitHub account had over 20,000 stars on security projects and represented the researcher's primary professional presence.
- This incident reignites debate between security researchers and vendors regarding responsible vulnerability disclosure practices.