If the clearly ill-informed ramblings of idiots causes multiple Microsoft developers, at least one of them very senior, to waste a week, I think I've found a IRL DDOS vector into their dev process...
If you really wanted to attack their vuln-investigation processes, you would simply let them conduct business as usual since it seems they don't know how to triage potential vulnerabilities. If you force the issue by conducting a DDoS, they will respond by developing a better triage system that de-prioritizes crank vuln reports more quickly. Not only will this defeat your DDoS attempt, but it will make them more effective at handling vuln reports going forward.
I remember an xkcd to that effect. Something like nerd sniping. Yes, I found it: http://xkcd.com/356/