Sign in

Microsoft Security Response Center

@msrc.microsoft.com
746 followers 10 following 172 posts

We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit microsoft.com/en-us/msrc.

PostsRepliesMedia
Microsoft Security Response Center @msrc.microsoft.com · 25/09/2026
Every security researcher starts somewhere. Firas Fatnassi shares how curiosity, persistence, and a commitment to learning shaped his journey from finding vulnerabilities as a teenager to becoming a respected voice in the security community. Read his story: www.microsoft.com/en-us/msrc/b...
Firas Fatnassi playing table tennis
010
Microsoft Security Response Center @msrc.microsoft.com · 19/09/2026
And a special thank you to our Security Villages for creating hands-on opportunities to learn, connect, and explore new skills throughout the event. We’re grateful to this incredible community and can’t wait to see you at the next BlueHat.
000
Microsoft Security Response Center @msrc.microsoft.com · 19/09/2026
Thank you to everyone who made this event possible, including our attendees, presenters, Microsoft teams, and Microsoft Most Valuable Researchers (MVRs) who traveled from around the world to be part of the conversation.
100
Microsoft Security Response Center @msrc.microsoft.com · 19/09/2026
That’s a wrap on BlueHat Asia. Over the past two days, security researchers, defenders, engineers, and security leaders came together to share new research, challenge assumptions, and strengthen the security community.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Jeff noted that stronger communities recover faster during times of disruption and change. As AI and other technologies reshape the industry, communities like BlueHat will become even more important places to learn, share ideas, build trust, and navigate what's next.
000
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Jeff described this as a golden age for both offense and defense. AI is creating opportunities to automate routine tasks, allowing researchers and defenders to spend more time on creative work and innovation. The goal isn't replacing human creativity, but creating more opportunities to apply it.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Jeff offered a prediction shaped by decades of experience: all problems at scale eventually become moderation problems. From spam and DDoS attacks to social networks, AI systems, and autonomous agents, successful communities depend on rules, governance, & the ability to manage bad behavior.
120
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
He also noted that it's impossible to please everyone all the time. Whether building products, communities, or security programs, leaders must understand who they are trying to serve and use that audience as their north star.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Another key lesson was communication. People often fear what they don't understand, and Jeff pointed to AI as a modern example. Rather than responding to fear with more fear, he encouraged the audience to focus on education and clear communication.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
It requires experimentation, puzzle solving, and a willingness to ask "what if?" Failure is part of the process, and many of the best ideas emerge from people willing to experiment and learn.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
As AI becomes increasingly capable, Jeff argued that these human connections remain as important as ever. He also reflected on what distinguishes hacking from information security. Infosec can be about sharpening tools and refining techniques, but hacking is about learning how to think.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Jeff described the hacking community as his first real community, a place where people learned from one another and built lasting relationships. That experience shaped one of the central themes of his talk: no one can know everything. Success depends on having trusted people you can ask for advice.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Drawing on experiences spanning the hacker community, government advisory roles, and industry leadership, Jeff explored what remains constant even as technology evolves: people, curiosity, and the power of community.
100
Microsoft Security Response Center @msrc.microsoft.com · 18/09/2026
Day 2 of BlueHat Asia opened with remarks from Jeff Moss, founder of DEF CON and Black Hat, who reflected on the lessons he's learned from building security communities and navigating decades of technological change.
110
Microsoft Security Response Center @msrc.microsoft.com · 17/09/2026
Good morning from Singapore and welcome to Day 1 of BlueHat Asia 2026! Registration opens at 8:30 AM, followed by opening remarks from Tom Gallagher, VP of Engineering, MSRC and our keynote, The Age of Experimentation, presented by Halvar Flake.
020
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
We're grateful for the presenters and MVRs who joined us in Singapore and look forward to the conversations, discoveries, and connections ahead.
000
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
A heartfelt thank you to our presenters and MVRs for sharing their expertise, insights, curiosity, and passion for advancing security. BlueHat is made possible by the incredible people who come together to learn from one another.
100
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
We started with a private tour of Singapore's iconic Gardens by the Bay before gathering at Marina Bay Sands, where BlueHat Asia presenters and Microsoft Most Valuable Researchers (MVRs) came together for an evening of conversation, connection, and collaboration.
100
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
As BlueHat Asia kicks off, we had the opportunity to spend an evening with some of the people who make this community so special.
110
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
The full agenda and speaker abstracts are now live: aka.ms/bluehatagenda
010
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
With two days of technical talks, keynotes, networking, and hands-on security villages, the agenda features talks from leading security researchers and Microsoft engineers, covering everything from AI-powered security research and cloud defense to identity attacks.
110
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
Attendees will also hear opening remarks from Jeff Moss, founder of DEF CON and Black Hat.
110
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
The event will feature keynote presentations from Halvar Flake, who will explore today’s "Age of Experimentation" in AI and engineering systems, and Tom Gallagher, VP of Engineering, MSRC, who will share his perspective on building security resilience at scale.
110
Microsoft Security Response Center @msrc.microsoft.com · 16/09/2026
Tomorrow, security researchers and defenders from around the world will gather in Singapore for BlueHat Asia 2026.
110
Microsoft Security Response Center @msrc.microsoft.com · 15/09/2026
We look forward to kicking off BlueHat Asia 2026 with Jeff's insights as we gather researchers, defenders, and industry leaders in Singapore for two days of technical research, collaboration, and discussion.
000
Microsoft Security Response Center @msrc.microsoft.com · 15/09/2026
Beyond his work building two of the world's most influential security events, Jeff has served in advisory roles spanning cybersecurity, Internet governance, and public policy, bringing a unique perspective on how the security landscape continues to evolve.
110
Microsoft Security Response Center @msrc.microsoft.com · 15/09/2026
Few individuals have had a greater influence on the security community than Jeff. Through DEF CON and Black Hat, he has helped shape generations of security researchers, practitioners, and industry leaders while advancing some of the most important conversations in cybersecurity.
110
Microsoft Security Response Center @msrc.microsoft.com · 15/09/2026
We're pleased to welcome Jeff Moss @thedarktangent.defcon.social.ap.brid.gy, founder of DEF CON and Black Hat, to BlueHat Asia 2026, where he'll deliver the conference opening remarks.
Jeff Moss
150
Microsoft Security Response Center @msrc.microsoft.com · 14/09/2026
We continue to evolve our bounty programs to reward impactful research and provide greater transparency into how submissions are evaluated. Learn more: www.microsoft.com/en-us/msrc/b...
010
Microsoft Security Response Center @msrc.microsoft.com · 14/09/2026
Key updates include: ➤ Up to $60,000 USD in awards for qualifying critical vulnerabilities ➤ New cross-tenant award multipliers for select scenarios ➤ More granular severity and impact-based award categories
110
Microsoft Security Response Center @msrc.microsoft.com · 14/09/2026
Researchers can now earn up to $60,000 USD for qualifying critical vulnerabilities through the updated Microsoft Dynamics 365 and Power Platform Bug Bounty Program.
110
Microsoft Security Response Center @msrc.microsoft.com · 10/09/2026
Through real-world examples and lessons learned, Tom will share perspectives on advancing security practices that anticipate threats, accelerate response, and strengthen protection before attackers have the opportunity to act.
000
Microsoft Security Response Center @msrc.microsoft.com · 10/09/2026
The keynote will explore how scale, simplicity, and disciplined engineering shape security outcomes, and why building resilience requires coordinated action across products, platforms, and people.
100
Microsoft Security Response Center @msrc.microsoft.com · 10/09/2026
Drawing on real-world incidents and pivotal moments in Microsoft's security journey, he will discuss how organizations can respond more effectively when attackers move faster than traditional remediation cycles.
100
Microsoft Security Response Center @msrc.microsoft.com · 10/09/2026
In his keynote, “Accelerated Response by Design,” Tom reflects on the challenge of securing one of the world's largest and most complex technology ecosystems.
100
Microsoft Security Response Center @msrc.microsoft.com · 10/09/2026
We're excited to announce Tom Gallagher Vice President of Engineering at the Microsoft Security Response Center (MSRC), as a keynote speaker at BlueHat Asia.
Tom Gallagher: BlueHat Asia keynote
130
Microsoft Security Response Center @msrc.microsoft.com · 08/09/2026
Learn more about this latest milestone in our transparency efforts: www.microsoft.com/en-us/msrc/b...
000
Microsoft Security Response Center @msrc.microsoft.com · 08/09/2026
Alongside this month's release, we're expanding machine-readable Vulnerability Exploitability eXchange (VEX) coverage to all Microsoft-assigned CVEs, providing customers with more consistent, machine-readable security information to help understand exposure and prioritize risk.
100
Microsoft Security Response Center @msrc.microsoft.com · 08/09/2026
Security updates for September are now available: msft.it/6018SZEg0
September 2026 Patch Tuesday
110
Microsoft Security Response Center @msrc.microsoft.com · 05/09/2026
Learn more in our blog and try out the new features for yourself: msft.it/6010aVvor
000
Microsoft Security Response Center @msrc.microsoft.com · 05/09/2026
Researcher Portal enhancements include Review with AI, improved report search and filtering, dashboard summary tiles, visual case status tracking, and a centralized activity feed that helps researchers stay informed throughout the vulnerability reporting process.
101
Microsoft Security Response Center @msrc.microsoft.com · 05/09/2026
Security researchers help make Microsoft's products and services more secure every day. To support that work, we're introducing new MSRC Researcher Portal enhancements designed to provide clearer guidance, better visibility into report status, and improved ways to manage vulnerability submissions.
MSRC Researcher Portal updates
120
Microsoft Security Response Center @msrc.microsoft.com · 11/08/2026
Security updates for August 2026 are now available. Details are here: msft.it/6018SZEg0
020
Microsoft Security Response Center @msrc.microsoft.com · 07/08/2026
Thank you for your contributions, your dedication, and your continued partnership. It was wonderful to spend time together celebrating the work we do as a community and the impact we can have together.
020
Microsoft Security Response Center @msrc.microsoft.com · 07/08/2026
Thank you to everyone who joined us for the MSRC Researcher Celebration at Black Hat USA. We're incredibly grateful to the security research community for the partnership, trust, and collaboration that help protect customers around the world.
240
Microsoft Security Response Center @msrc.microsoft.com · 03/08/2026
A record-breaking year for Microsoft's Bounty Programs! This year, Microsoft awarded more than $20 million to 562 security researchers, the highest total payout and largest number of researchers recognized in program history. Read the full blog: aka.ms/microsoft-bo...
Microsoft Bounty Year in Review
030
Microsoft Security Response Center @msrc.microsoft.com · 31/07/2026
Storm-2945, a sub-cluster of Midnight Blizzard, has been observed compromising hospitality-related networks to steal credentials, gain access to cloud environments, and target travelers. Read the latest Microsoft Threat Intelligence blog for details.
000
Microsoft Security Response Center @msrc.microsoft.com · 18/07/2026
⏰ Final reminder: Registration for BlueHat Asia closes tonight at 11:59 PM. Secure your spot before registration closes: aka.ms/bluehatreg
000
Microsoft Security Response Center @msrc.microsoft.com · 16/07/2026
Learn more and view the full leaderboard: www.microsoft.com/en-us/msrc/blog/2026/07/congratulations-to-the-top-msrc-2026-q2-security-researchers
Q2 leaderboard
000
Microsoft Security Response Center @msrc.microsoft.com · 16/07/2026
🥇Asaf Cohen (XBREACH.AI) 🥈C46F3708A45EF0041BD0A49DDAEA0E25 🥉Ron 4. Thanatos Tian (HKPolyU) & wgg & 2st with Diffract 5. haowei yan 6. fce141fd6b42fcec05c1285b15d8f999 7. Ofek Levin 8. pwn2addr 9. Kim Seung Chan (@mylostchristmas) 10. Jianyang Song
110