Microsoft credited the likely lone actor behind the EncryptHub alias for reporting two Windows security flaws.EncryptHub, a controversial figure with ties to cybercrime, pursued both legitimate security research and engaged in cybercriminal activity.He reported two vulnerabilities to Microsoft, addressing a security feature bypass issue and a file explorer spoofing vulnerability.Despite his considerable hacking skills, EncryptHub made OPSEC mistakes that exposed his cybercrime operations.