Sign in

Microsoft Security Response Center

@msrc.microsoft.com
746 followers 10 following 172 posts

We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit microsoft.com/en-us/msrc.

PostsRepliesMedia
Microsoft Security Response Center @msrc.microsoft.com · 25/09/2026
Every security researcher starts somewhere. Firas Fatnassi shares how curiosity, persistence, and a commitment to learning shaped his journey from finding vulnerabilities as a teenager to becoming a respected voice in the security community. Read his story: www.microsoft.com/en-us/msrc/b...
Firas Fatnassi playing table tennis
010
Microsoft Security Response Center @msrc.microsoft.com · 19/09/2026
That’s a wrap on BlueHat Asia. Over the past two days, security researchers, defenders, engineers, and security leaders came together to share new research, challenge assumptions, and strengthen the security community.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Day 2 of BlueHat Asia opened with remarks from Jeff Moss, founder of DEF CON and Black Hat, who reflected on the lessons he's learned from building security communities and navigating decades of technological change.
110
Microsoft Security Response Center @msrc.microsoft.com · 17/09/2026
Good morning from Singapore and welcome to Day 1 of BlueHat Asia 2026! Registration opens at 8:30 AM, followed by opening remarks from Tom Gallagher, VP of Engineering, MSRC and our keynote, The Age of Experimentation, presented by Halvar Flake.
020
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
As BlueHat Asia kicks off, we had the opportunity to spend an evening with some of the people who make this community so special.
110
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
Tomorrow, security researchers and defenders from around the world will gather in Singapore for BlueHat Asia 2026.
110
Microsoft Security Response Center @msrc.microsoft.com · 15/09/2026
We're pleased to welcome Jeff Moss @thedarktangent.defcon.social.ap.brid.gy, founder of DEF CON and Black Hat, to BlueHat Asia 2026, where he'll deliver the conference opening remarks.
Jeff Moss
150
Microsoft Security Response Center @msrc.microsoft.com · 14/09/2026
Researchers can now earn up to $60,000 USD for qualifying critical vulnerabilities through the updated Microsoft Dynamics 365 and Power Platform Bug Bounty Program.
110
Microsoft Security Response Center @msrc.microsoft.com · 10/09/2026
We're excited to announce Tom Gallagher Vice President of Engineering at the Microsoft Security Response Center (MSRC), as a keynote speaker at BlueHat Asia.
Tom Gallagher: BlueHat Asia keynote
130
Microsoft Security Response Center @msrc.microsoft.com · 08/09/2026
Security updates for September are now available: msft.it/6018SZEg0
September 2026 Patch Tuesday
110
Microsoft Security Response Center @msrc.microsoft.com · 05/09/2026
Security researchers help make Microsoft's products and services more secure every day. To support that work, we're introducing new MSRC Researcher Portal enhancements designed to provide clearer guidance, better visibility into report status, and improved ways to manage vulnerability submissions.
MSRC Researcher Portal updates
120
Microsoft Security Response Center @msrc.microsoft.com · 11/08/2026
Security updates for August 2026 are now available. Details are here: msft.it/6018SZEg0
020
Microsoft Security Response Center @msrc.microsoft.com · 07/08/2026
Thank you to everyone who joined us for the MSRC Researcher Celebration at Black Hat USA. We're incredibly grateful to the security research community for the partnership, trust, and collaboration that help protect customers around the world.
240
Microsoft Security Response Center @msrc.microsoft.com · 03/08/2026
A record-breaking year for Microsoft's Bounty Programs! This year, Microsoft awarded more than $20 million to 562 security researchers, the highest total payout and largest number of researchers recognized in program history. Read the full blog: aka.ms/microsoft-bo...
Microsoft Bounty Year in Review
030
Microsoft Security Response Center @msrc.microsoft.com · 31/07/2026
Storm-2945, a sub-cluster of Midnight Blizzard, has been observed compromising hospitality-related networks to steal credentials, gain access to cloud environments, and target travelers. Read the latest Microsoft Threat Intelligence blog for details.
000
Microsoft Security Response Center @msrc.microsoft.com · 18/07/2026
⏰ Final reminder: Registration for BlueHat Asia closes tonight at 11:59 PM. Secure your spot before registration closes: aka.ms/bluehatreg
000
Microsoft Security Response Center @msrc.microsoft.com · 16/07/2026
Congratulations to all the researchers recognized in the MSRC 2026 Q2 Security Researcher Leaderboard! This quarter marks the final quarterly points-based leaderboard as we continue the evolution of our researcher recognition program.
111
Microsoft Security Response Center @msrc.microsoft.com · 14/07/2026
Security updates for July 2026 are now available. Details are here: msft.it/6018SZEg0
Patch Tuesday July
010
Microsoft Security Response Center @msrc.microsoft.com · 08/07/2026
Today, we're proud to recognize the Top 100 Microsoft 2026 Most Valuable Researchers (MVRs). Security researchers play a critical role in helping protect customers by identifying and reporting vulnerabilities across Microsoft products and services.
130
Microsoft Security Response Center @msrc.microsoft.com · 26/06/2026
How does a standard user become a global admin? At BlueHat 2026, Dylan Ryan-Zilavy and MSRC Senior Security Researcher Cameron Vincent examine a real-world vulnerability that enabled privilege escalation from a low-privileged user to Global Administrator in Microsoft Entra.
121
Microsoft Security Response Center @msrc.microsoft.com · 09/06/2026
Security updates for June 2026 are now available. Details are here: msft.it/6018SZEg0 #PatchTuesday
June 2026 Patch Tuesday
030
Microsoft Security Response Center @msrc.microsoft.com · 09/06/2026
The BlueHat Asia Call for Papers closes June 15. If you’ve been considering submitting, now’s the time: aka.ms/BlueHatAsiaCFP
030
Microsoft Security Response Center @msrc.microsoft.com · 21/05/2026
BlueHat Asia is heading to Singapore on September 17–18! 👉Apply now for your chance to join us: aka.ms/bluehatreg Applications close July 17. #BlueHat
010
Microsoft Security Response Center @msrc.microsoft.com · 16/05/2026
Less than one month to go ⏳ The BlueHat Asia Call for Papers closes June 15. Don't miss your chance to share your research! Submit your talk today: aka.ms/BlueHatAsiaCFP
010
Reposted by Microsoft Security Response Center
Microsoft Exchange @msftexchange.bsky.social · 14/05/2026
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub! 🦋 techcommunity.microsoft.com/blog/Exchang...
techcommunity.microsoft.com
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub
We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE-2026-42897.  
074
Microsoft Security Response Center @msrc.microsoft.com · 12/05/2026
Security updates for May 2026 are now available. Details are here: msft.it/6018SZEg0
Security Updates for May 2026
130
Microsoft Security Response Center @msrc.microsoft.com · 08/05/2026
Update to the Windows Insider Preview bounty program: General Awards for Elevation of Privilege and Information Disclosure are now split by finishing privilege, with award ranges increasing to $1,000–$8,000. Learn more: www.microsoft.com/en-us/msrc/b...
022
Microsoft Security Response Center @msrc.microsoft.com · 07/05/2026
Day 2 at BlueHat 2026 wrapped with new learnings, fresh perspectives, and continued discussions across the security community. Take a look at some of the highlights from Day 2: www.youtube.com/shorts/-kxsM...
youtube.com
BlueHat 2026: Day 2
YouTube video by Microsoft Security Response Center (MSRC)
000
Microsoft Security Response Center @msrc.microsoft.com · 06/05/2026
Day 2 is underway at BlueHat. Here’s a look back at Day 1. A strong start, with the security community coming together to connect, share insights, and tackle real-world challenges. Watch the highlights ⬇️ #BlueHat
000
Microsoft Security Response Center @msrc.microsoft.com · 06/05/2026
Good morning, BlueHat, and welcome back to day 2 ☀️ We’ll start with opening remarks from Tom Gallagher, VP of Engineering, MSRC, followed by a keynote from Mark Russinovich, CTO, Deputy CISO, and Technical Fellow for Microsoft Azure. View the day 2 agenda: aka.ms/bh26agenda #BlueHat
BlueHat 2026
010
Microsoft Security Response Center @msrc.microsoft.com · 05/05/2026
At BlueHat 2026, Taesoo Kim, VP Security Research, Microsoft took the stage for the Day 1 keynote to discuss what’s next for security as AI systems begin to scale vulnerability discovery and remediation in ways we haven’t seen before. #BlueHat
Taesoo Kim, VP of Security Research, Microsoft
110
Microsoft Security Response Center @msrc.microsoft.com · 05/05/2026
Good morning, BlueHat! ☀️We’re excited to start Day 1 with you. Grab some breakfast and join us for opening remarks from Tom Gallagher, VP of Engineering, MSRC, followed by our keynote from Taesoo Kim, VP of Security Research at Microsoft. You can find the full agenda here: aka.ms/bh26agenda
140
Microsoft Security Response Center @msrc.microsoft.com · 05/05/2026
Thank you to all of our BlueHat speakers who joined us for the welcome reception this evening. It was great to connect and kick off the event. We are looking forward to welcoming everyone to BlueHat tomorrow.
040
Microsoft Security Response Center @msrc.microsoft.com · 01/05/2026
We’re excited to announce that Dr. Abhilasha Bhargav-Spantzel, Microsoft AI, and Jason Martin, Director, Adversarial Research, Hidden Layer, will be speaking at BlueHat with their session, “From Trusted Agents to Adversaries: Securing Agentic AI in the Age of Prompt Injection.”
Meet our BlueHat 2026 speakers: Abhilasha Bhargav-Spantzel and Jason Martin
121
Microsoft Security Response Center @msrc.microsoft.com · 30/04/2026
🎤 BlueHat Redmond speaker announcement We’re excited to announce our next speaker, Matt Swann, VP & Distinguished Engineering at Microsoft.
Meet Our BlueHat 2026 Speakers: Matt Swann
100
Microsoft Security Response Center @msrc.microsoft.com · 28/04/2026
We’ve updated the Microsoft 365 Insider Builds on Windows Bounty Program to better recognize impactful research and improve the submission experience for our community. Learn more: www.microsoft.com/en-us/msrc/b...
Microsoft 365 Insider Bounty program updates
021
Microsoft Security Response Center @msrc.microsoft.com · 27/04/2026
We’re thrilled to announce Taesoo Kim as the Day 1 BlueHat keynote speaker. Taesoo is Vice President of Security Research at Microsoft and a Professor at Georgia Tech in the School of Cybersecurity and Privacy and the School of Computer Science.
Meet Our BlueHat Redmond Speakers; Taesoo Kim
110
Microsoft Security Response Center @msrc.microsoft.com · 24/04/2026
At BlueHat Asia, Cameron Vincent and Brian McNulty walk through real-world variant hunting inside MSRC, including: • Common multi-tenant authorization pitfalls • What not to trust in JWT claims • How tools like Impostor help uncover risk at scale Watch the session: www.youtube.com/watch?v=LykX...
youtube.com
INTERN(al) MSRC variant hunting: From multi-tenant authorization to MCP
YouTube video by Microsoft Security Response Center (MSRC)
011
Microsoft Security Response Center @msrc.microsoft.com · 23/04/2026
Thank you to everyone who joined us for the MSRC Researcher Celebration at Black Hat Asia. It was great to connect with so many in the community and spend time sharing ideas and conversations.
MSRC researcher celebration at Black Hat Asia
010
Microsoft Security Response Center @msrc.microsoft.com · 22/04/2026
🎤 BlueHat Redmond speaker announcement We're excited to announce Varsha Chahal and Henrique Pereira Senior Security Engineers at Microsoft, will be speaking at BlueHat Redmond with their talk, “Gotta Catch’em All: Hunting Azure Anonymous Functions in the Wild.” #BlueHat
Meet our BlueHat Redmond speakers: Varsha Chahal and Henrique Pereira
010
Microsoft Security Response Center @msrc.microsoft.com · 21/04/2026
📣BlueHat Asia Call for Papers now open! 📣 We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and more! 📍Singapore | September 17–18 🗓️CFP deadline: June 15 Submit now: aka.ms/BlueHatAsiaCFP
124
Microsoft Security Response Center @msrc.microsoft.com · 14/04/2026
Security updates for April 2026 are now available. Details are here: msft.it/6018SZEg0 #PatchTuesday
April 2026 Patch Tuesday
030
Microsoft Security Response Center @msrc.microsoft.com · 13/04/2026
Through Zero Day Quest, Microsoft awarded $2.3 million to security researchers for eligible findings across cloud and AI services. Read how this collaboration is helping strengthen protections for customers in our blog post from Tom Gallagher, VP of Engineering, MSRC: msft.it/6017Q7p73
Zero Day Quest 2026: $2.3 million awarded for vulnerability research
021
Microsoft Security Response Center @msrc.microsoft.com · 10/04/2026
🗓️ Mark your calendars 🗓️ BlueHat is headed to Singapore, September 17–18. Call for Papers and registration announcements coming soon. 👀
045
Microsoft Security Response Center @msrc.microsoft.com · 07/04/2026
Congratulations to all the researchers recognized in this quarter’s MSRC 2026 Q1 Security Researcher Leaderboard! Thanks to all the researchers who partnered with us for your hard work and continued dedication to securing our customers. Learn more in our blog post: lnkd.in/gRViAQ2U
Quarterly leaderboard
120
Microsoft Security Response Center @msrc.microsoft.com · 03/04/2026
🚨 New $100,000 RCE award added 🚨 We’ve introduced a new $100,000 Remote Code Execution (RCE) award to the Microsoft Hyper‑V bounty program, recognizing high‑impact guest escape research and rewarding high-quality submissions. Learn more and submit: msft.it/6019Q0oxB
🚨 New $100,000 RCE award added 🚨
We’ve introduced a new $100,000 Remote Code Execution (RCE) award to the Microsoft Hyper‑V bounty program, recognizing high‑impact guest escape research and rewarding high-quality submissions.
030
Microsoft Security Response Center @msrc.microsoft.com · 02/04/2026
🚨Still time to apply to BlueHat Redmond! 🚨 Due to high interest, we’ve extended the application deadline through April 6. Join the security research community in Redmond on May 5–6. Apply here: aka.ms/bluehatreg
010
Microsoft Security Response Center @msrc.microsoft.com · 27/03/2026
🚨 Last chance for BlueHat Redmond Registration closes March 31 for one of the most unique security research events of the year. Join the security community on May 5-6 for two days of insights, collaboration, and cutting-edge discussions. 👉Register now: aka.ms/bluehatreg
000
Microsoft Security Response Center @msrc.microsoft.com · 17/03/2026
We’re excited to welcome some of the world’s top security researchers to Zero Day Quest 2026. We’re grateful to every researcher who qualified and joined us in person, as well as those participating remotely. Their work and partnership with Microsoft help protect customers and the world.
MSRC and security researchers at Zero Day QuestMSRC and security researchers at Zero Day Quest
031
Microsoft Security Response Center @msrc.microsoft.com · 13/03/2026
Planning to join us at BlueHat Redmond this May? Registration is open, but it closes March 31. Submit your application to attend now: aka.ms/bluehatreg
aka.ms
BlueHat 2026 Reg
001