Google has said that Ormandy was working independently of his employer, and Ormandy has defended himself on Twitter, writing that he only revealed the bug on the Full Disclosure mailing list after first attempting to negotiate a 60-day deadline for Microsoft to patch the flaw.
FORBES: Microsoft Security Bug Exposed By Google Researcher Now Exploited More Than 10,000 Times