Microsoft Security Response Center's Avatar

Microsoft Security Response Center

@msrc.microsoft.com

We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit http://microsoft.com/en-us/msrc.

669
Followers
10
Following
59
Posts
12.11.2024
Joined
Posts Following

Latest posts by Microsoft Security Response Center @msrc.microsoft.com

It’s go time. ⏰
Submit your BlueHat Redmond CFP by midnight PT tonight.

06.03.2026 17:10 👍 0 🔁 0 💬 0 📌 0

Phishing‑as‑a‑service continues to lower the bar for attackers. New analysis from Microsoft Threat Intelligence breaks down Tycoon2FA, its AiTM capabilities, and how Microsoft, working with partners, disrupted the service, along with recommended detection and defense actions.

05.03.2026 18:50 👍 0 🔁 0 💬 0 📌 0
Zhiniang Peng, Microsoft MVR and Zero Day Quest qualifier

Zhiniang Peng, Microsoft MVR and Zero Day Quest qualifier

Security research never stops. Meet Zhiniang Peng, Microsoft MVR and two‑time Zero Day Quest Qualifier, whose persistence and curiosity continue to push security research forward.

👉 Read his story on the MSRC blog: www.microsoft.com/en-us/msrc/b...

05.03.2026 01:26 👍 0 🔁 0 💬 0 📌 0

⏰ Just 3 days left to submit to the BlueHat Redmond CFP!

Don’t miss the chance to share your work with the security community. Submit your abstract: aka.ms/BH26CFP

#BlueHat

04.03.2026 18:32 👍 3 🔁 4 💬 0 📌 1

Still thinking about submitting to BlueHat Redmond? We're opening a final Call for Papers submission windows through Friday, March 6.

Submit your abstract here: aka.ms/BH26CFP

01.03.2026 17:46 👍 0 🔁 1 💬 0 📌 0

🚨 Last call 🚨

The BlueHat Call for Papers closes Feb 28.

If you have original security research, hard won lessons, or insights the community can learn from, now’s the time to submit.

Submit before the CFP closes tomorrow: aka.ms/BH26CFP

27.02.2026 18:27 👍 0 🔁 1 💬 0 📌 0

Only 4 more days to submit your BlueHat Redmond CFP. We can’t wait to see what you share with the community.

Submit your paper by February 28, 2026: aka.ms/BH26CFP

25.02.2026 18:41 👍 3 🔁 0 💬 0 📌 1

Only 5 more days to submit your BlueHat Redmond CFP.
We can’t wait to see what you share with the community.

#BlueHat

24.02.2026 21:29 👍 1 🔁 0 💬 0 📌 0
Felix (security researcher) artwork

Felix (security researcher) artwork

Every security researcher starts somewhere. For Felix, it began with arcades and led all the way to Azure.

Now a Microsoft MVR and Zero Day Quest qualifier, Felix shares the persistence and mindset that shaped his path into security research in our latest blog: msft.it/63323Qn7BN

20.02.2026 18:14 👍 0 🔁 0 💬 0 📌 0

Inspired to share your own research? The BlueHat Redmond Call for Papers is open through February 28. Submit your talk: aka.ms/BH26CFP

19.02.2026 17:14 👍 0 🔁 0 💬 0 📌 0
BlueHat Asia: Cross-tenant RCEs at scale: Breaking Azure and getting caught
BlueHat Asia: Cross-tenant RCEs at scale: Breaking Azure and getting caught YouTube video by Microsoft Security Response Center (MSRC)

From Microsoft Purview and integration runtimes to Azure Synapse and Data Factory, this talk highlights how shared compute, connector design, and fragile mitigations can quietly create powerful attack paths.

Watch the full talk on YouTube: www.youtube.com/watch?v=cYCj...

19.02.2026 17:14 👍 2 🔁 0 💬 1 📌 0

What does cross-tenant RCE at scale actually look like in the cloud?

In this BlueHat Asia talk, Microsoft MVR Tzah Pahima walks through real-world research into Azure shared infrastructure, from an initial signal to cross tenant remote code execution (and a very real “getting caught” moment).

19.02.2026 17:14 👍 1 🔁 0 💬 1 📌 0
Video thumbnail

🎉 BlueHat Redmond registration is officially open! 🎉

We’re excited to welcome the security community back to Microsoft’s Redmond campus for BlueHat 2026, taking place May 5–6, 2026. Don’t miss your chance to connect, learn, and share with the community.

➡️Register now: aka.ms/bluehatreg

18.02.2026 19:20 👍 5 🔁 2 💬 0 📌 0
BlueHat 2023: Mark Russinovich Keynote
BlueHat 2023: Mark Russinovich Keynote YouTube video by Microsoft Security Response Center (MSRC)

Watch his 2023 keynote here: www.youtube.com/watch?v=8hXB...

17.02.2026 21:06 👍 0 🔁 0 💬 0 📌 0

Mark previously delivered a keynote at BlueHat 2023, and we’re excited to welcome him back.

17.02.2026 21:05 👍 0 🔁 0 💬 1 📌 0

A frequent speaker at Microsoft Ignite, Microsoft Build, and RSA Conference, Mark is also the author of Windows Internals, Troubleshooting with the Sysinternals Tools, and the cyber‑thriller novels Zero Day, Trojan Horse, and Rogue Code.

17.02.2026 21:05 👍 0 🔁 0 💬 1 📌 0

Mark is CTO, Deputy CISO, and Technical Fellow for Microsoft Azure. A widely recognized expert in distributed systems, operating systems, and cybersecurity, Mark holds a Ph.D. in computer engineering from Carnegie Mellon University and co‑founded Winternals Software before joining Microsoft in 2006.

17.02.2026 21:05 👍 0 🔁 0 💬 1 📌 0

We’re excited to announce @markrussinovich.bsky.social as a keynote speaker at BlueHat Redmond, from May 5-6, 2026.

17.02.2026 21:05 👍 3 🔁 0 💬 1 📌 0

Mark is CTO, Deputy CISO, and Technical Fellow for Microsoft Azure. A widely recognized expert in distributed systems, operating systems, and cybersecurity, Mark holds a Ph.D. in computer engineering from Carnegie Mellon University and co‑founded Winternals Software before joining Microsoft in 2006.

17.02.2026 19:39 👍 0 🔁 0 💬 0 📌 0
Video thumbnail

Got some downtime this weekend?

It’s the perfect time to submit your talk to BlueHat Redmond. The Call for Papers is open now. No paper required, just a great idea and a detailed abstract.

Learn more in our blog post: www.microsoft.com/en-us/msrc/b...

Submit your abstract here: aka.ms/BH26CFP

14.02.2026 02:27 👍 2 🔁 1 💬 0 📌 1
Fixing the script: Journey to reduce XSS exposure

Fixing the script: Journey to reduce XSS exposure

XSS persists not because it’s misunderstood, but because mitigations often miss where execution actually happens. In this post, we share what’s proven effective in practice, why common fixes fail, and how to move toward sustainable XSS defense: www.microsoft.com/en-us/msrc/b...

12.02.2026 18:32 👍 0 🔁 0 💬 0 📌 0
Patch Tuesday February 2026

Patch Tuesday February 2026

Security updates for February 2026 are now available. Details are here: msft.it/6018SZEg0

#PatchTuesday #SecurityUpdateGuide

10.02.2026 17:54 👍 1 🔁 1 💬 0 📌 1
The evolution of the Microsoft security researcher leaderboard

The evolution of the Microsoft security researcher leaderboard

We’re evolving how researcher impact is recognized. Beginning with the July 2026 MVR leaderboard, rankings will reflect bounty award amounts, and all valid reports will be acknowledged with honorable mentions. Details: www.microsoft.com/en-us/msrc/b...

06.02.2026 18:11 👍 2 🔁 0 💬 0 📌 1
BlueHat Asia: Exploiting the pipeline: Real-world CI/CD vulnerabilities and how to secure them
BlueHat Asia: Exploiting the pipeline: Real-world CI/CD vulnerabilities and how to secure them YouTube video by Microsoft Security Response Center (MSRC)

CI/CD pipelines are a high‑value target. At BlueHat Asia, Harish Poornachander breaks down how real‑world DevSecOps missteps lead to pipeline poisoning, secret exfiltration, and privilege escalation and how to stop them.

Watch the talk on YouTube: www.youtube.com/watch?v=eZhk...

01.02.2026 01:39 👍 5 🔁 1 💬 0 📌 0
BlueHat Asia keynote: Where the mind is without fear: Building a secure, AI-powered world
BlueHat Asia keynote: Where the mind is without fear: Building a secure, AI-powered world YouTube video by Microsoft Security Response Center (MSRC)

In her BlueHat Asia keynote, Dr. Abhilasha Bhargav-Spantzel shared a grounded take on AI-era security. She focused on building systems that hold up under pressure without leading from fear, and on the importance of strong architecture, trust, and accountability: www.youtube.com/watch?v=IVN-...

30.01.2026 19:08 👍 0 🔁 0 💬 0 📌 0
Wouter wtm

Wouter wtm

You don’t pick the bugs. The bugs pick you.”

Meet Wouter, Microsoft MVR and Zero Day Quest 2026 qualifier, and read his security research journey: www.microsoft.com/en-us/msrc/b...

#ZeroDayQuest

29.01.2026 19:10 👍 0 🔁 0 💬 0 📌 0
Video thumbnail

Kicking off the Call for Papers for BlueHat Redmond ⚽️

BlueHat brings together security researchers and responders to exchange ideas, experiences, and best practices.

Bring your best ideas, because security is a team sport.

Submit your paper by February 28, 2026: aka.ms/BH26CFP

23.01.2026 17:17 👍 3 🔁 3 💬 0 📌 3
Video thumbnail

Save the date. Score a spot at BlueHat Redmond ⚽️

BlueHat Redmond is back and takes place May 5–6, 2026. Watch this space for details as we get closer to kickoff.

21.01.2026 20:36 👍 1 🔁 0 💬 0 📌 1
January 2026 Patch Tuesday

January 2026 Patch Tuesday

Security updates for January 2026 are now available. Details are here: msft.it/6018SZEg0

#PatchTuesday #SecurityUpdateGuide

13.01.2026 18:03 👍 5 🔁 0 💬 0 📌 1
MSRC Q4 2025 leaderboard

🥇Vaisha Bernard of Eye Security (https://msft.it/6013tFEZt)
🥈Lakshmi Vignesh S
🥉Anonymous 
4. Shrinivasan Sekar
5. Matthew Jensen
6. P1hcn
7. Jianyang Song
8. wh1tc@Kunlun lab& devoke & Zhiniang Peng with HUST
9. Anonymous
10. Boolgombear

MSRC Q4 2025 leaderboard 🥇Vaisha Bernard of Eye Security (https://msft.it/6013tFEZt) 🥈Lakshmi Vignesh S 🥉Anonymous 4. Shrinivasan Sekar 5. Matthew Jensen 6. P1hcn 7. Jianyang Song 8. wh1tc@Kunlun lab& devoke & Zhiniang Peng with HUST 9. Anonymous 10. Boolgombear

Congratulations to all the researchers recognized in this quarter’s MSRC 2025 Q4 Security Researcher Leaderboard! Thanks to all the researchers who partnered with us for your hard work and continued dedication to securing our customers.

Learn more in our blog post: msft.it/6012tFEZs

05.01.2026 19:02 👍 2 🔁 0 💬 0 📌 0