Sources: Microsoft and Google haven't been contacted by Assange, two days after he said WikiLeaks would share details of CIA hacking tools with tech firms
Thomas Fox-Brewster / Forbes :
Context & Ripple Effects
WikiLeaks' dump of CIA hacking documents put device-level compromise in the spotlight — coverage of the cache noted it targets devices rather than apps, which is why Signal's and WhatsApp's encryption held up. Assange then publicly offered to share exploit details with the affected tech firms so they could patch.
This report is the reality check on that offer: two days on, sources say neither Microsoft nor Google has heard from him. The two companies also carry baggage here — back in 2015, [[a:825768|WikiLeaks demanded answers after learning Google had handed three staffers' emails to the US government]] — so any direct channel between them starts from a position of mutual suspicion.
First-order effects
- Microsoft's and Google's security teams are left without the exploit details Assange dangled, meaning any vulnerable devices stay unpatched until WikiLeaks moves or the details surface another way.
Second-order effects
- WikiLeaks' next step, per later reporting, was to require tech firms to agree to conditions before receiving the zero-day details — turning a straightforward vulnerability disclosure into a negotiation over terms.
Third-order effects
- If exploit disclosures run through conditional, intermediary-controlled channels instead of direct vendor outreach, patching timelines stretch and vendors lean harder into encryption-first designs like those that withstood this cache — while their already-strained trust in US intelligence agencies deepens.
The trend: Vulnerability disclosure is shifting from direct researcher-to-vendor channels toward leak-driven releases gated by intermediaries' own conditions.