Threat Picture
Latest Cybersecurity News

Tavis Ormandy: The Researcher Behind Cloudbleed and Zenbleed

Antivirus engines, web servers and processors all came under his scrutiny. His findings forced fixes and arguments over disclosure.
By Charles Joseph · Updated
Share
Share
Copy URL

Somewhere in the San Francisco Bay Area there's an Englishman who reads other people's software the way most of us read the news, and whose findings have forced emergency patches out of Microsoft, Symantec, Cloudflare, AMD and Intel.

Tavis Ormandy isn't the kind of researcher who sends a polite email and waits. He found his first fame by giving Microsoft five days, and spent the next fifteen years arguing, in public, that the people selling you security software were often making you less safe.

The vendors learned to dread his name. Then, in October 2025, after nearly twenty years at Google, he posted a one-line goodbye.

Tavis Ormandy at a Glance

  • An English researcher who joined Google in the mid-2000s, Ormandy built a reputation as one of the most prolific bug hunters in the industry, with a particular appetite for antivirus software.
  • In 2010 he published a Windows zero-day five days after telling Microsoft about it, and the security world split over whether he was a hero or, in one memorable phrase, a "narcissistic vulnerability pimp."
  • His "Sophail" paper tore apart Sophos's antivirus engine, and in 2016 he showed that Symantec and Norton products could be taken over by an email nobody opened.
  • He was a founding member of Google's Project Zero in 2014, the team that gives vendors 90 days to fix what it finds.
  • In February 2017 he spotted Cloudflare's servers leaking strangers' passwords and cookies, a bug the world came to know as Cloudbleed.
  • Three months later he and Natalie Silvanovich found what he called "the worst Windows remote code exec in recent memory," and Microsoft patched it in three days.
  • He then moved from software to silicon, uncovering AMD's Zenbleed flaw and Intel's Reptar bug in 2023 and a microcode-signing weakness across five generations of AMD chips in 2025.
  • On October 10, 2025, he left Google after nearly twenty years to work as an independent researcher.
Sponsored

The Life of Tavis Ormandy

Ormandy's Early Years

Tavis Ormandy is from England and, by his own description, now lives in the San Francisco Bay Area. He keeps his biography to a couple of sentences, and that's about all the public record says about his life before Google.

He joined the company in the mid-2000s and became part of its security team. When Wired profiled Google's hackers in 2014, it described him as "an English researcher who has a reputation as one of the industry's most prolific bug hunters."

What set him apart was his choice of targets. While others hunted bugs in browsers, Ormandy went after the security software itself.

Five Days

In January 2010 Ormandy published details of a Windows flaw after waiting seven months for Microsoft to respond. It was a warning shot.

That June he found a hole in the Help and Support Center of Windows XP, told Microsoft, and five days later published the details along with an exploit. Within days, criminals were using it to push a Trojan from a hacked website.

The reaction was ferocious. Security blogger Graham Cluley called it "utterly irresponsible behaviour" and asked whether Ormandy was proud of himself. Two Verizon researchers coined the phrase "narcissistic vulnerability pimps" for people who did such things.

Ormandy's position never changed: vendors fix things when they're embarrassed, and users deserve to know. Microsoft issued a stopgap "Fix it" tool and then a patch.

Sponsored

Sophail

Next he turned on the industry whose job was supposedly protecting everyone. His paper Sophail picked apart the Sophos antivirus engine and argued that its presence on a machine opened new doors rather than closing them.

The pattern repeated. In 2016 he found that Trend Micro's password manager could be made to run arbitrary commands, one of a long list of security products that failed his inspection.

In June 2013 he went around Microsoft again, releasing exploit code for a Windows kernel bug after what Business Insider called "a long-running skirmish he's had with the security folks in Redmond." This time his employer had his back: Google had just announced a tougher disclosure policy of its own.

Project Zero

In July 2014 Google made the approach official. It announced Project Zero, a team of elite bug hunters led by Chris Evans, whose business cards read "Troublemaker," with Ormandy, Ben Hawkes and Ian Beer among the first members and George Hotz as the intern.

The team's rule was simple and, for vendors, unpleasant: 90 days to fix a bug, then it goes public.

Ormandy's biggest Project Zero splash came in June 2016, when he dug into Symantec and Norton antivirus. The products unpacked suspicious files inside the Windows kernel, using open-source code the company "hadn't updated in at least 7 years."

"These vulnerabilities are as bad as it gets," he wrote. "They don't require any user interaction, they affect the default configuration, and the software runs at the highest privilege levels possible." One of them was wormable.

Cloudbleed

On Friday, February 17, 2017, Ormandy noticed garbage in web pages served through Cloudflare. The garbage turned out to be other people's data: cookies, passwords and private messages leaking from the memory of servers that fronted some six million websites.

He tweeted, "Could someone from Cloudflare security urgently contact me," without even tagging the company. It reached the right people within fifteen minutes.

Cloudflare's engineers had a first fix in place 47 minutes after his report and a global one in under seven hours, then set about purging cached copies of the leaked pages. The company's incident report thanked "one of the world's top security research teams." The world called it Cloudbleed.

Sponsored

The Worst Windows Bug in Recent Memory

Three months later, in May 2017, Ormandy and his Project Zero colleague Natalie Silvanovich found a flaw in the malware protection engine built into every modern version of Windows. Simply scanning a booby-trapped email or file was enough to take over the machine.

His Friday-night tweets called it "the worst Windows remote code exec in recent memory" and warned that attacks "work against a default install, don't need to be on the same LAN, and it's wormable."

Microsoft patched it in three days. The man who'd given them five days in 2010 posted: "Still blown away at how quickly @msftsecurity responded."

The hits kept coming: a Grammarly browser extension that let websites read everything you typed, a Ghostscript hole with no patch available, and in 2019 a 20-year-old Windows subsystem called CTF that let a lowly program hijack others on the same machine.

Word Processors and Silicon

Ormandy's hobbies are as particular as his work. In 2022 he resurrected Lotus 1-2-3 for Unix and then WordPerfect for Unix, text-mode relics of the 1990s, and got them running on modern Linux.

Then he went below the operating system. In 2023 he built a fuzzer that ran random instruction sequences through a CPU and checked whether the hardware agreed with its own answers.

It found Zenbleed, a flaw in AMD's Zen 2 processors that let one program read data belonging to another, even across virtual machines. He reported it to AMD on May 15, 2023, and AMD shipped new microcode. That November the same method turned up Reptar, a bug in recent Intel chips that could knock a processor into what he called "a glitch state where the normal rules don't apply."

In February 2025 Google disclosed that Ormandy and four colleagues had found AMD using an insecure hash in its signature check for microcode updates, which meant an administrator could load unofficial microcode onto five generations of Zen chips.

The Last Day

By 2025 Ormandy was working in Google's information security group rather than Project Zero, and still writing. That summer he published a much-argued-over critique of Anubis, the anime-catgirl proof-of-work wall that open-source sites had put up against AI scrapers.

On October 10, 2025, he posted: "A personal update... after nearly 20 years at Google, today is my last day! I'm going to be working on independent research for the foreseeable future, then who knows!"

His website now introduces him in five words: "I'm an independent vulnerability researcher." The posts haven't stopped.

Sponsored

Tavis Ormandy: Full Disclosure

The argument Ormandy started in 2010 is over, and he won it. Ninety-day deadlines, public bug trackers and vendors who patch in days rather than months are now the norm, and a good part of that is down to one Englishman who refused to wait.

He also proved something uncomfortable about the security industry: the software sold to protect you runs with the highest privileges on your machine, and it's often the softest target there.

Whatever he does next, he'll probably tell you about it before the vendor does.

QUOTE:

"Amateurs hack systems, professionals hack people."