FireEye takes security firm to court over vulnerability disclosure
Jeremy Kirk / CIO.com :
Context & Ripple Effects
The lawsuit lands four days after a researcher disclosed a zero-day vulnerability in FireEye's products, and one day before the company pushed back publicly: it said the flaw affected only .005% of customers and framed the court action against ERNW as protecting sensitive proprietary information rather than suppressing disclosure itself.
That framing matters because FireEye sells detection and response — credibility with the research community is part of the product. The suit tests whether a vendor can simultaneously claim to support coordinated disclosure and take a discloser to court, at a moment when FireEye was still building out its threat-intelligence business ahead of the iSight Partners acquisition.
First-order effects
- ERNW now faces an active injunction fight over published technical details, with legal cost and precedent risk attached to any further publication on the flaw.
- FireEye's own customers get a dual message this week: exposure is narrow (.005% per the company), but the vendor will litigate to control what details circulate.
Second-order effects
- Other security vendors watching the case gain a litigation template for responding to disclosures they consider over-broad, shifting leverage from the researcher's publish-or-patch timeline to the courtroom.
- Independent researchers may route around vendors they see as litigious — favoring anonymous channels or full disclosure — which degrades exactly the early-warning flow FireEye's intelligence business depends on.
Third-order effects
- If suing disclosers becomes a normalized first response, coordinated-disclosure norms harden into legal-first processes where lawyers, not engineers, set what gets published — an outcome that would cut against the industry's stated support for responsible disclosure.
- The episode foreshadows the standing tension in the sector between treating vulnerability data as a trade secret and as public-safety information, a line regulators have since been drawn into policing.
The trend: Vulnerability disclosure is drifting from a technical coordination norm into a legal battleground, with vendors willing to sue the researchers who expose their flaws.