A record-breaking year for Microsoft's Bounty Programs! This year, Microsoft awarded more than $20 million to 562 security researchers, the highest total payout and largest number of researchers recognized in program history. Read the full blog: aka.ms/microsoft-bo...
Microsoft Security Response Center
@msrc.microsoft.com
We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit http://microsoft.com/en-us/msrc.
Storm-2945, a sub-cluster of Midnight Blizzard, has been observed compromising hospitality-related networks to steal credentials, gain access to cloud environments, and target travelers. Read the latest Microsoft Threat Intelligence blog for details.
Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, compromising hospitality-related networks worldwide to steal credentials, access cloud environments, and deliver malware to travelers. msft.it/63328aBnhE
⏰ Final reminder: Registration for BlueHat Asia closes tonight at 11:59 PM. Secure your spot before registration closes: aka.ms/bluehatreg
BlueHat Asia is heading to Singapore on September 17–18! 👉Apply now for your chance to join us: aka.ms/bluehatreg Applications close July 17. #BlueHat
Congratulations to all the researchers recognized in the MSRC 2026 Q2 Security Researcher Leaderboard! This quarter marks the final quarterly points-based leaderboard as we continue the evolution of our researcher recognition program.
Today, we're proud to recognize the Top 100 Microsoft 2026 Most Valuable Researchers (MVRs). Security researchers play a critical role in helping protect customers by identifying and reporting vulnerabilities across Microsoft products and services.
How does a standard user become a global admin? At BlueHat 2026, Dylan Ryan-Zilavy and MSRC Senior Security Researcher Cameron Vincent examine a real-world vulnerability that enabled privilege escalation from a low-privileged user to Global Administrator in Microsoft Entra.
The BlueHat Asia Call for Papers closes June 15. If you’ve been considering submitting, now’s the time: aka.ms/BlueHatAsiaCFP
📣BlueHat Asia Call for Papers now open! 📣 We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and more! 📍Singapore | September 17–18 🗓️CFP deadline: June 15 Submit now: aka.ms/BlueHatAsiaCFP
BlueHat Asia is heading to Singapore on September 17–18! 👉Apply now for your chance to join us: aka.ms/bluehatreg Applications close July 17. #BlueHat
Less than one month to go ⏳ The BlueHat Asia Call for Papers closes June 15. Don't miss your chance to share your research! Submit your talk today: aka.ms/BlueHatAsiaCFP
📣BlueHat Asia Call for Papers now open! 📣 We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and more! 📍Singapore | September 17–18 🗓️CFP deadline: June 15 Submit now: aka.ms/BlueHatAsiaCFP
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub! 🦋 techcommunity.microsoft.com/blog/Exchang...
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub
We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE-2026-42897.
techcommunity.microsoft.com
Update to the Windows Insider Preview bounty program: General Awards for Elevation of Privilege and Information Disclosure are now split by finishing privilege, with award ranges increasing to $1,000–$8,000. Learn more: www.microsoft.com/en-us/msrc/b...
Day 2 at BlueHat 2026 wrapped with new learnings, fresh perspectives, and continued discussions across the security community. Take a look at some of the highlights from Day 2: www.youtube.com/shorts/-kxsM...
BlueHat 2026: Day 2
YouTube video by Microsoft Security Response Center (MSRC)
youtube.com
Day 2 is underway at BlueHat. Here’s a look back at Day 1. A strong start, with the security community coming together to connect, share insights, and tackle real-world challenges. Watch the highlights ⬇️ #BlueHat
Good morning, BlueHat, and welcome back to day 2 ☀️ We’ll start with opening remarks from Tom Gallagher, VP of Engineering, MSRC, followed by a keynote from Mark Russinovich, CTO, Deputy CISO, and Technical Fellow for Microsoft Azure. View the day 2 agenda: aka.ms/bh26agenda #BlueHat
At BlueHat 2026, Taesoo Kim, VP Security Research, Microsoft took the stage for the Day 1 keynote to discuss what’s next for security as AI systems begin to scale vulnerability discovery and remediation in ways we haven’t seen before. #BlueHat
Good morning, BlueHat! ☀️We’re excited to start Day 1 with you. Grab some breakfast and join us for opening remarks from Tom Gallagher, VP of Engineering, MSRC, followed by our keynote from Taesoo Kim, VP of Security Research at Microsoft. You can find the full agenda here: aka.ms/bh26agenda
Thank you to all of our BlueHat speakers who joined us for the welcome reception this evening. It was great to connect and kick off the event. We are looking forward to welcoming everyone to BlueHat tomorrow.
We’re excited to announce that Dr. Abhilasha Bhargav-Spantzel, Microsoft AI, and Jason Martin, Director, Adversarial Research, Hidden Layer, will be speaking at BlueHat with their session, “From Trusted Agents to Adversaries: Securing Agentic AI in the Age of Prompt Injection.”
🎤 BlueHat Redmond speaker announcement We’re excited to announce our next speaker, Matt Swann, VP & Distinguished Engineering at Microsoft.
We’ve updated the Microsoft 365 Insider Builds on Windows Bounty Program to better recognize impactful research and improve the submission experience for our community. Learn more: www.microsoft.com/en-us/msrc/b...
We’re thrilled to announce Taesoo Kim as the Day 1 BlueHat keynote speaker. Taesoo is Vice President of Security Research at Microsoft and a Professor at Georgia Tech in the School of Cybersecurity and Privacy and the School of Computer Science.
At BlueHat Asia, Cameron Vincent and Brian McNulty walk through real-world variant hunting inside MSRC, including: • Common multi-tenant authorization pitfalls • What not to trust in JWT claims • How tools like Impostor help uncover risk at scale Watch the session: www.youtube.com/watch?v=LykX...
INTERN(al) MSRC variant hunting: From multi-tenant authorization to MCP
YouTube video by Microsoft Security Response Center (MSRC)
youtube.com
Thank you to everyone who joined us for the MSRC Researcher Celebration at Black Hat Asia. It was great to connect with so many in the community and spend time sharing ideas and conversations.
🎤 BlueHat Redmond speaker announcement We're excited to announce Varsha Chahal and Henrique Pereira Senior Security Engineers at Microsoft, will be speaking at BlueHat Redmond with their talk, “Gotta Catch’em All: Hunting Azure Anonymous Functions in the Wild.” #BlueHat
📣BlueHat Asia Call for Papers now open! 📣 We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and more! 📍Singapore | September 17–18 🗓️CFP deadline: June 15 Submit now: aka.ms/BlueHatAsiaCFP
Security updates for April 2026 are now available. Details are here: msft.it/6018SZEg0 #PatchTuesday
Through Zero Day Quest, Microsoft awarded $2.3 million to security researchers for eligible findings across cloud and AI services. Read how this collaboration is helping strengthen protections for customers in our blog post from Tom Gallagher, VP of Engineering, MSRC: msft.it/6017Q7p73