We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit microsoft.com/en-us/msrc.

Redmond
Every security researcher starts somewhere. In our latest researcher spotlight, Firas Fatnassi (@Fatnass1F1ras) shares how curiosity, persistence, and a commitment to learning shaped his journey from finding vulnerabilities as a teenager to becoming a respected voice in the security community. Read his story in the MSRC blog: msft.it/6018a9qwj
1
2
21
4,467
We're excited to partner again with Wiz for ZERODAY.CLOUD 2026 at Black Hat Europe! This annual open-source cloud hacking competition brings together researchers from around the world to identify critical vulnerabilities and make the cloud a safer place. 🤝 Put your skills to the test. Register your exploit now: zeroday.cloud/
Replying to @wiz
@Wiz Research presents ZERODAY.CLOUD 2026! 🕵️‍♀️ Our open-source cloud hacking competition is back at @BlackHatEvents Europe with @awscloud, @MsftSecIntel & @googlecloud . Hunt vulns for a $6.5M prize pool! 💰🏆 Register now: zeroday.cloud/2026-competiti…
1
6
37
7,009
Microsoft Security Response Center retweeted
Friday marked the final day of BlueHat Asia, with security professionals from across the community coming together to share research and exchange ideas. The day began with opening remarks from Jeff Moss (Founder, DEF CON & Black Hat), followed by a keynote from Tom Gallagher (VP of Engineering, MSRC), focused on practical security improvements, tactical mitigations, and raising the cost for attackers. From technical sessions to conversations in the Security Villages, Day 2 highlighted the value of collaboration in helping protect customers and strengthen security across the ecosystem. This video features highlights from the keynote by Tom Gallagher (@secbughunter), along with perspectives from Cameron Vincent (@SecretlyHidden1), Senior Security Researcher, MSRC, and Asem Eleraky @Melotover), Senior Penetration Tester, PayMob.
1
14
2,145
Microsoft Security Response Center retweeted
At BlueHat Asia, Chumy Tsai (@rm_rf_chumy) and Katherine Chen shared how they chained multiple SharePoint vulnerabilities into a full pre-authentication remote code execution (RCE) exploit. The research began with a JWT authentication bypass that enabled impersonation of arbitrary SharePoint users, including administrators, by abusing flaws in token validation and identity mapping. The second half of the talk focused on Flow2Shell (CVE-2026-47298), a SharePoint Workflow vulnerability. The researchers showed how workflows are built from XOML and rule files, then walked through four separate workflow validation mechanisms intended to prevent abuse. Through a series of bypasses involving type validation, rule validation, runtime checks, and workflow caching behavior, they were able to evade SharePoint's protections and execute malicious code on a fully patched server. One of the most interesting findings involved SharePoint's workflow cache. A malicious workflow assembly could be loaded into memory before validation errors were surfaced. By triggering the workflow a second time, SharePoint would reuse the cached assembly and skip portions of the validation pipeline, ultimately leading to code execution. Beyond the technical exploit chain, the talk highlighted the value of detailed vulnerability research. The complete proof-of-concept and root cause analysis enabled MSRC to quickly assess severity, identify additional variants, begin remediation, and better protect customers. As the presenters noted, impactful security research is not just about finding a bug, but proving impact, understanding root causes, and helping defenders address entire classes of vulnerabilities.
6
38
5,411
Microsoft Security Response Center retweeted
What happens when an AI assistant inherits the privileges of the user it's helping? At BlueHat Asia, Johann Rehberger (@wunderwuzzi23) discussed how SQL Copilot in SQL Server Management Studio can become a powerful target when connected to highly privileged accounts. Through his demos, he showed how "read-only" assumptions can break down, how prompt injection techniques can influence AI behavior, and why security boundaries matter just as much as model instructions. The talk offered a deep dive into AI security, database permissions, and the unintended risks that emerge when assistants are granted access to sensitive environments. Johann Rehberger's key message was simple: trust, permissions, and execution context matter.
1
1
17
4,975
Microsoft Security Response Center retweeted
How do cross-tenant vulnerabilities happen in complex cloud environments? At BlueHat Asia, Haakon Wik Gulbrandsrud walked through his research into Azure Logic Apps and API connections, showing how a single architectural root cause led to multiple cross-tenant security issues. Through a series of real-world examples, he demonstrated how understanding platform internals, not just hunting for bugs, can uncover high-impact vulnerabilities hiding in plain sight. The talk offered a fascinating look at the research process itself: tracing connections, mapping architecture, and asking what could go wrong at every step until the answers lead somewhere unexpected.
1
9
1,414
Microsoft Security Response Center retweeted
At BlueHat Asia, Salim Chawro, Corporate Vice President of Microsoft Cloud Security, and Zeeshan Syed, Vice President of Microsoft Cloud Security, shared how Microsoft is rethinking proactive defense as cloud environments continue to grow in size and complexity. They argued that traditional point-in-time security reviews can no longer keep pace with services that are constantly changing and threat landscapes that are accelerating with AI. The talk introduced Argus, Microsoft's agentic security assurance system, which brings together code, identities, configurations, dependencies, runtime signals, and architectural context to help teams identify control gaps, uncover root causes, model attack paths, and prioritize remediation. Rather than focusing on individual vulnerabilities, the approach helps teams understand how risks connect across an entire service and address broader classes of security issues. The speakers also discussed how defenders have a unique advantage in the AI era: access to the full context of their environments. By combining that context with agentic workflows, Microsoft is working to deliver continuous security assurance at a scale that would be impossible through manual review alone. With more than 90% of Argus findings confirmed as genuine security issues, the system is helping teams conduct deeper reviews in hours instead of weeks.
1
5
1,318
Attackers don't wait, and neither can defenders. Great keynote from Tom Gallagher on protecting customers and our systems through tactical mitigation and rapid response.
Tom Gallagher (@secbughunter), VP of Engineering at MSRC, opened Day 2 of BlueHat Asia with his keynote, Accelerated Response by Design, examining a challenge many security teams are already facing: AI is making it easier and faster to find vulnerabilities, which means defenders need to be ready to respond at a completely different pace. As the number of reported vulnerabilities continues to grow, Tom argued that finding issues is only part of the equation. The bigger challenge is reducing risk before attackers have a chance to take advantage of it. Throughout the keynote, Tom focused on the idea of tactical mitigation: taking action to protect customers quickly, even when a full fix isn't ready yet. Using examples from recent incidents, including CVE-2026-21509 and CVE-2026-42897, he showed how many attacks depend on a chain of events going exactly right. Break one link in that chain, and the attack often falls apart. Sometimes that can be as simple as a configuration change, blocking a specific action, or using existing security controls to make a vulnerable path unreachable while engineers work on a long-term fix. Rather than waiting for the perfect solution, Tom encouraged attendees to think about what they can do immediately to reduce exposure and disrupt attack paths. His challenge to the audience was simple: understand how attacks work against your systems and identify the one piece you can take away from the attacker. Tom closed by returning to a theme that ran throughout the talk: attackers don't wait, and defenders can't afford to wait either. The goal is to mitigate first, reduce risk quickly, and then fast-follow with the full fix
1
1
6
5,154
From AI and moderation to lifelong learning and strong communities, Jeff Moss shared a thoughtful perspective on how the security industry can continue to adapt and thrive through change.
Day 2 of BlueHat Asia opened with remarks from Jeff Moss, founder of DEF CON and Black Hat, who reflected on the lessons he's learned from building security communities and navigating decades of technological change. Drawing on experiences spanning the hacker community, government advisory roles, and industry leadership, Jeff explored what remains constant even as technology evolves: people, curiosity, and the power of community. Jeff described the hacking community as his first real community, a place where people learned from one another and built lasting relationships. That experience shaped one of the central themes of his talk: no one can know everything. Success depends on having trusted people you can turn to for advice, feedback, and new perspectives. As AI becomes increasingly capable, Jeff argued that these human connections remain as important as ever. He also reflected on what distinguishes hacking from information security. Information security can be about sharpening tools and refining techniques, but hacking is fundamentally about learning how to think. It requires experimentation, puzzle solving, and a willingness to ask "what if?" Failure is part of the process, and many of the best ideas emerge from people willing to experiment and learn. Another key lesson was communication. People often fear what they don't understand, and Jeff pointed to AI as a modern example. Rather than responding to fear with more fear, he encouraged the audience to focus on education and clear communication. He also noted that it's impossible to please everyone all the time. Whether building products, communities, or security programs, leaders must understand who they are trying to serve and use that audience as their north star. Looking ahead, Jeff offered a prediction shaped by decades of experience: all problems at scale eventually become moderation problems. From spam and DDoS attacks to social networks, AI systems, and autonomous agents, successful communities depend on rules, governance, and the ability to manage bad behavior. At the same time, Jeff described this as a golden age for both offense and defense. AI is creating opportunities to automate routine tasks, allowing researchers and defenders to spend more time on creative work and innovation. The goal isn't replacing human creativity, but creating more opportunities to apply it. He closed by returning to the importance of community. Jeff noted that stronger communities recover faster during times of disruption and change. As AI and other technologies reshape the industry, communities like BlueHat will become even more important places to learn, share ideas, build trust, and navigate what's next.
1
9
4,924
Day 1 delivered. Looking forward to another day of research, learning, and collaboration at BlueHat Asia.
Day 1 of BlueHat Asia featured technical talks, new research, and hands-on experiences in the Security Villages, bringing together researchers, defenders, and industry leaders from across the security community. We're getting ready to kick off Day 2 with opening remarks from Jeff Moss, followed by a keynote from Tom Gallagher (@secbughunter). Looking forward to another day of learning, collaboration, and conversations that help shape the future of security.
12
4,888
Microsoft Security Response Center retweeted
Sometimes the most interesting vulnerabilities are not caused by a single bug, but by assumptions that quietly break over time. At BlueHat Asia, Microsoft MVRs Zhu Qing and b2ahex (@b2ahex) shared their research into the Windows DirectX kernel, uncovering dozens of vulnerabilities spanning local privilege escalation, guest-to-host attack paths in Hyper-V, information disclosure, and denial-of-service scenarios. Their work resulted in 32 reported vulnerabilities and 26 confirmed CVEs at the time of submission. From user-mode interactions with dxgkrnl to host-side processing in GPU-PV environments, the researchers demonstrated how subtle violations of security assumptions can create powerful exploitation opportunities. Beyond the vulnerability findings themselves, the talk offered a practical framework for security research: trace every path from attacker-controlled input to the final privileged action, and verify that security guarantees still hold at each step. It was a compelling look at how deep technical analysis can uncover entire classes of vulnerabilities across complex systems.
2
27
3,412
Microsoft Security Response Center retweeted
Great research often starts with a simple question and a bit of curiosity. At BlueHat Asia, Matthew Jensen and Sonal Shrivastava shared how a quest to build a better Azure deployment experience led to the discovery of multiple Azure Portal vulnerabilities. What began as a single XSRF finding evolved into a deeper exploration of Azure's deployment controls, uncovering additional attack paths involving ArmApiControl, GraphApiControl, and the Azure batch endpoint. The talk discussed how traditional assumptions about CSRF have changed in modern cloud environments, where trusted portal components can act on behalf of authenticated users. Along the way, the researchers demonstrated how seemingly isolated primitives could be chained together, how missed-fix variants emerged, and why securing cloud control planes requires thinking beyond classic web security models. Just as importantly, the talk provided an inside look at the remediation process. Microsoft engineering teams responded with a combination of rapid mitigations, class-level protections, stronger consent models, and defense-in-depth improvements designed to address the underlying pattern rather than individual instances. A key takeaway: vulnerabilities evolve, and defenses must evolve with them. Understanding the underlying primitive is often more important than fixing a single entry point
1
4
1,592
Microsoft Security Response Center retweeted
The most impactful vulnerabilities are not always the ones that look severe at first glance. At BlueHat Asia, Asem Eleraky (@Melotover) challenged attendees to rethink how client-side vulnerabilities are evaluated, arguing that the real question is not "What can I steal?" but "What can I make the application do?" Through two real-world case studies, the session showed how seemingly limited injection flaws can be chained into much larger security outcomes. The first case study showed how a client-side vulnerability could be leveraged into a full account takeover by exploiting trust assumptions around identity workflows and OTP-based authentication. The second explored how application-layer weaknesses could be used to hijack Microsoft 365 Copilot interactions, highlighting the importance of securing not only AI models but also the platforms, frameworks, and trust boundaries surrounding them. A key theme throughout the talk was that understanding context matters. By digging deeper into how applications work, researchers can uncover unexpected paths to impact that go far beyond the original bug. As security architectures evolve, proving real-world impact remains one of the most important parts of effective research.
2
3
14
2,750
Microsoft Security Response Center retweeted
Account takeovers do not always start with sophisticated exploit chains. Sometimes they begin with a design decision, an overlooked edge case, or an unexpected interaction between features. At BlueHat Asia, Félix Boulet, a Microsoft Most Valuable Researcher (MVR), and Callum Carney (@callum_infosec), Senior Security Researcher, MSRC, discussed four real-world paths to compromising an Entra ID account, demonstrating how identity security can be affected by stale accounts, state reuse, parsing behavior, MFA assumptions, and Conditional Access logic. The talked highlighted how seemingly small gaps can combine into meaningful security risks. Beyond the technical findings, the talk offered a rare look at both sides of the process: how vulnerabilities are discovered by researchers and how Microsoft investigates, assesses, remediates, and coordinates fixes across teams. The result was a practical look at modern identity security, showing how research, product teams, and vulnerability response work together to strengthen defenses. One key takeaway: securing identity platforms requires more than preventing individual bugs. It requires understanding how features, workflows, and security controls interact in the real world.
1
2
6
1,520
Microsoft Security Response Center retweeted
Sometimes the biggest discoveries start with a simple question: What happens if I try this? At BlueHat Asia, Vaisha Bernard (@the1bernard), a two-time Microsoft Most Valuable Researcher (MVR) from Eye Security, and Cameron Vincent (@secretlyhidden1), Senior Security Researcher, MSRC shared how a seemingly small test, swapping a GET request for a PUT request, ultimately led to five critical vulnerabilities and a broader effort to help secure Microsoft's ecosystem. The talk discussed how curiosity, persistence, and a deep understanding of cloud infrastructure uncovered a pattern involving Azure Front Door, Azure Blob Storage, and overprivileged managed identities. What began as a single finding evolved into a larger variant hunting effort across Microsoft, helping teams identify and remediate similar issues at scale. A recurring theme throughout the talk was the importance of challenging assumptions. Even when a test seems unlikely to succeed, that one unexpected result can reveal something much larger. The presentation also reinforced a fundamental security principle: apply least privilege wherever possible and avoid granting managed identities more access than they truly need. Key takeaways for researchers: • Follow the breadcrumbs. Small discoveries can uncover much larger security issues. • Look beyond the initial vulnerability. Understanding how systems are architected can reveal additional attack paths and impact. • Pay attention to patterns. Multiple findings can point to broader systemic risks that warrant deeper investigation. • The most impactful research doesn't just find a bug. It helps drive security improvements across an entire ecosystem.
5
25
2,696
Microsoft Security Response Center retweeted
Sometimes the hardest bugs to find live in the gaps between security controls. At BlueHat Asia, Eugene Lim (@spaceraccoonsec) discussed a local privilege escalation vulnerability in Microsoft Defender for macOS, showing how a race condition in Defender's peer-validation logic could be combined with authorization bypasses and file read/write primitives to ultimately achieve code execution as root. Along the way, the talk highlighted the security challenges of privileged inter-process communication on macOS, the importance of correctly validating process identity, and the subtle platform differences that can turn a familiar bug class into a completely new exploitation path. The research also served as a reminder that securing cross-platform software means understanding not just how each operating system works, but how security assumptions can change from one platform to another. The talk closed with a broader lesson for defenders and developers alike: building cross-platform software is hard, but building it securely is even harder.
1
1
11
1,716
As Tom Gallagher (@secbughunter) shared in his opening remarks at BlueHat Asia, security advances through collaboration. Excited to see researchers and engineers from around the world come together at BlueHat Asia to learn, share ideas, and build trust. Thanks to Halvar Flake (@halvarflake) for kicking things off with a thought-provoking keynote.
BlueHat Asia 2026 is off to an amazing start in Singapore. Kicking off the event, Tom Gallagher (@secbughunter), VP of Engineering, MSRC, welcomed attendees from nearly every continent and reflected on BlueHat's evolution from an internal Microsoft gathering into a forum where security researchers and Microsoft engineers come together to learn from one another, share perspectives, and build lasting trust. At its core, BlueHat has always been about collaboration, bringing together the people who find vulnerabilities and the people who fix them, all with the shared goal of making technology more secure. Following Tom's remarks, Halvar Flake (@halvarflake) opened the conference with a keynote exploring what he called an "Age of Experimentation" in software engineering and security. Drawing on lessons from Rowhammer, Spectre, and today's AI systems, Halvar argued that the industry is moving away from purely deterministic computing toward a world where experimentation, statistics, and empirical evidence matter more than ever. As AI becomes embedded in engineering and security workflows, he challenged attendees to think more like scientists: test assumptions, measure carefully, and be comfortable operating in systems that don't always produce the same result twice. Despite the uncertainty, his message was ultimately optimistic. We are living through a period of technological change that may rival the internet in significance, and the right response is to stay curious, keep experimenting, and focus on understanding what's possible.
2
2
21
5,424
Kicking off BlueHat Asia with an incredible group of presenters and MVRs. Thank you for the expertise, curiosity, and collaboration you bring to the security community.
As BlueHat Asia kicks off, we had the opportunity to spend an evening with some of the people who make this community so special. We started with a private tour of Singapore's iconic Gardens by the Bay before gathering at Marina Bay Sands, where BlueHat Asia presenters and Microsoft Most Valuable Researchers (MVRs) came together for an evening of conversation, connection, and collaboration. A heartfelt thank you to our presenters and MVRs for sharing their expertise, insights, curiosity, and passion for advancing security. BlueHat is made possible by the incredible people who come together to learn from one another. We're grateful for the presenters and MVRs who joined us in Singapore and look forward to the conversations, discoveries, and connections ahead.
1
1
23
4,909
Microsoft Security Response Center retweeted
Tomorrow, security researchers and defenders from around the world will gather in Singapore for BlueHat Asia 2026. The event will feature keynote presentations from Halvar Flake, who will explore today’s "Age of Experimentation" in AI and engineering systems, and Tom Gallagher, VP of Engineering, MSRC, who will share his perspective on building security resilience at scale. Attendees will also hear opening remarks from Jeff Moss, founder of DEF CON and Black Hat. With two days of technical talks, keynotes, networking, and hands-on security villages, the agenda features talks from leading security researchers and Microsoft engineers, covering everything from AI-powered security research and cloud defense to identity attacks, SQL Copilot security, Azure vulnerabilities, and offensive security techniques. The full agenda and speaker abstracts are now live: aka.ms/bluehatagenda
1
2
25
2,684
Microsoft Security Response Center retweeted
We're pleased to welcome Jeff Moss, founder of DEF CON and Black Hat, to BlueHat Asia 2026, where he'll deliver the conference opening remarks. Few individuals have had a greater influence on the security community than Jeff. Through DEF CON and Black Hat, he has helped shape generations of security researchers, practitioners, and industry leaders while advancing some of the most important conversations in cybersecurity. Beyond his work building two of the world's most influential security events, Jeff has served in advisory roles spanning cybersecurity, Internet governance, and public policy, bringing a unique perspective on how the security landscape continues to evolve. We look forward to kicking off BlueHat Asia 2026 with Jeff's insights as we gather researchers, defenders, and industry leaders in Singapore for two days of technical research, collaboration, and discussion.
2
1
9
1,702