Microsoft Suspends Open Source Dev Accounts, Blocks Critical Updates

Microsoft Suspends Open Source Dev Accounts, Blocks Critical Updates

Microsoft has recently suspended developer accounts vital for maintaining several high-profile open-source projects, leaving these projects unable to release new software builds and crucial security patches for Windows users. According to Cyber Threat Intelligence, the affected accounts were suspended without proper notification or a clear, swift process for reinstatement. This has effectively cut off maintainers from publishing updates for widely used tools.

The list of impacted projects is significant and includes essential software like the WireGuard VPN, VeraCrypt encryption utility, MemTest86 for RAM diagnostics, and Windscribe VPN. Developers from these projects have reported receiving no prior warnings or explanations for the account terminations. VeraCrypt developer Mounir Idrassi stated that Microsoft support channels only yielded automated replies, preventing any human contact to resolve the issue. This inability to push Windows updates is a major setback, especially given Windows’ large user base.

Similar experiences have been echoed by maintainers of other popular projects, including WireGuard and MemTest86. These developers have spent weeks attempting to reach Microsoft support without success. The lack of communication and the apparent impossibility of appealing the suspensions have created a critical situation for the open-source community relying on these tools, potentially leaving Windows users vulnerable due to delayed security fixes.

What This Means For You

  • Security teams should diversify their reliance on specific software vendors or platforms for critical tools, especially when those tools are open-source projects maintained by individuals. Have contingency plans ready in case a vital open-source component's development or distribution is suddenly disrupted by external factors, such as platform account suspensions.
πŸ”Ž
Stay ahead of this threat Search threats by organization, set watchlist alerts, or get a weekly SIEM digest with detection rules matched to your vendors β€” inside Telegram.
Open Intel Bot β†’

Related coverage

Laravel Lang Packages Hijacked to Deploy Credential-Stealing Malware

A supply chain attack has compromised Laravel Lang localization packages, exposing developers to credential-stealing malware. Attackers manipulated GitHub version tags to inject malicious code into...

threat-inteldata-breachmalwareidentitytools
/SCW Research /MEDIUM /⚙ 3 Sigma

npm Boosts Supply Chain Security with 2FA-Gated Staged Publishing

GitHub has rolled out new controls for npm, significantly enhancing software supply chain security. The Hacker News reports that these features, now generally available, introduce...

threat-intelvulnerabilityidentitytools
/SCW Vulnerability Desk /HIGH /⚑ 2 IOCs /⚙ 2 Sigma

Packagist Supply Chain Attack Infects 8 Packages with Linux Malware

A new, coordinated supply chain attack has compromised eight packages on Packagist. The attack injects malicious code designed to retrieve and execute a Linux binary...

threat-intelvulnerabilitymalwaretools
/SCW Vulnerability Desk /HIGH /⚑ 3 IOCs /⚙ 2 Sigma