Is It 'Code Red' for Windows OS?
What do you do when you find a serious vulnerability in Microsoft server OS source code? You could tell the whole world about it, or you could keep schtum and just inform Microsoft. Or, of course, you could tell no one and use the knowledge to go and attack other systems.
What would the Russians do? That's an interesting question, and I guess we are about to find out because Microsoft recently signed a deal with the Russian Federal Security Service giving it access to source code for Windows Server 2008 R2, Office 2010 and SQL Server.