Security @ Microsoft & BlueHat Podcast Co Host

Joined February 2014
185 Photos and videos
Wendy retweeted
At an aquarium in Japan, after closing time, some clever little otter pups help their grandpa tidy up their toys. As a reward, he gives them ice cubes
1,646
30,890
266,182
9,032,706
Wendy retweeted
🎤 BlueHat Redmond speaker announcement We're excited to announce Varsha Chahal and Henrique Pereira (@ikkebr), Senior Security Engineers at Microsoft, will be speaking at BlueHat Redmond with their talk, “Gotta Catch’em All: Hunting Azure Anonymous Functions in the Wild.” Azure Functions often expose anonymous HTTP endpoints, creating a broad and overlooked attack surface. In this session, Varsha and Henrique share how they identified and exploited vulnerabilities at scale, leading to 40 MSRC cases, including multiple high-impact issues. From CodeQL to automated exploitation pipelines, learn how small misconfigurations can turn into critical cloud risks and how defenders can better secure serverless workloads. #BlueHat
3
9
612
Lets GOOOOOOO!!!! This is so exciting. Submit papers y'all! @mattjay @__muscles @JohnathanKuskos Im looking at you all :-)
📣The BlueHat Asia Call for Papers is now open! 📣 BlueHat brings together security researchers and defenders to exchange ideas, experiences, and best practices. We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and related areas across the security landscape. 📍Singapore | September 17–18, 2026 🗓️CFP deadline: June 15, 2026 Submit your paper now: aka.ms/BlueHatAsiaCFP
1
1
4
712
There is a lot of momentum around AI in cybersecurity and its ability to improve security outcomes at scale. At Microsoft, we are applying these capabilities to our long-standing work with the community to find and mitigate vulnerabilities more quickly and augmenting our security and development toolsets so we can better protect customers and Microsoft. Read more: msft.it/6011QNHuf
5
10
6,366
You did AMAZING!!!!!!
Mar 20
Very very pleased! Thank you very much @secbughunter , @Microsoft and @msftsecresponse. If there will be a next year, I promise to bring my A-game and good health 😀🫶🏻 #ZeroDayQuest
1
2
169
Heck yeah we did!!! Thank you for all you do!
They put us on the jumbotron at Climate Pledge Arena 😭🏒 #ZeroDayQuest @msftsecresponse
3
79
Wendy retweeted
All those XSS payloads… and @secbughunter still beat them by just handing over a cookie 🍪😄 Day 2 of #ZeroDayQuest @msftsecresponse
1
2
9
2,397
I don’t have the word to fully articulate how great this event is. The benefits are layered and invaluable. It’s fun. It’s collaborative but most of all, it’s protecting you, the customers! Thank you researchers for what you do and thank you @msftsecresponse for this event.
Day 1 of the Zero Day Quest Onsite Hacking Event is in the books and we’ve kicked off Day 2. We welcomed top security researchers from around the world to Microsoft’s Redmond campus for a day of live hacking, collaboration, and connection. Researchers worked side-by-side with Microsoft engineers and product teams to identify vulnerabilities across our AI and cloud platforms. Lots of amazing reports and discussions flowed throughout the day with MSRC, product teams, and the researchers themselves all driving security forward together. We wrapped the day with a Seattle Kraken vs. Tampa Bay Lightning game in Seattle (tough loss, but the vibes were strong!). We’re incredibly grateful to the security researcher community. Your work makes a real impact in helping protect customers. #ZeroDayQuest
1
65
Great weather, great people, and great collaboration!
Today, we’re welcoming top security researchers from around the world to Microsoft’s Redmond campus for the first official day of the Zero Day Quest Onsite Hacking Event. They’ll collaborate with Microsoft engineers and product teams to uncover vulnerabilities across our AI and cloud platforms over the next two days. We’re thankful for the security researcher community and the impact their work has in helping protect customers. #ZeroDayQuest
74
What a great day!!! Lets go #ZeroDayQuest!!!
We’re excited to welcome some of the world’s top security researchers to Zero Day Quest 2026 🎉 We kicked off the onsite hacking event with bowling, followed by dinner and drinks with incredible views. It’s the start of a full week of security research, collaboration with Microsoft teams, and social events including a Kraken hockey game, a brunch cruise, and more. We’re grateful to every researcher who qualified and joined us in person, as well as those participating remotely. Their work and partnership with Microsoft help protect customers and communities around the world. #ZeroDayQuest
3
161
Super excited about this!
The global security research community plays a critical role in protecting Microsoft customers. As Tom Gallagher (@secbughunter), VP of Engineering at MSRC, shares in today’s announcement, we’re evolving how researcher impact is recognized. Starting with the July 2026 Most Valuable Researcher (MVR) leaderboard, rankings will be based on bounty award amounts, providing a consistent signal that aligns recognition with vulnerability severity and security outcomes. We’re also introducing honorable mentions to recognize all researchers who submit valid vulnerability reports, independent of ranking. Read the full announcement for more details: msft.it/6013Q3zlv
2
174
In our latest blog, Cameron Vincent (@SecretlyHidden1), Senior Security Researcher at MSRC, features the work of MSRC intern and security researcher, Brian McNulty (@brianjmcnulty), who uncovered 22 critical vulnerabilities in just two months. Learn how the MSRC team leverages automation and tools like IMPOSTR to identify risky multi-tenant apps, why robust authentication and authorization are essential, and how new protocols like Model Context Protocol (MCP) are shaping the future of secure AI integration. This blog covers: • Real-world attack scenarios and variant hunting strategies • Securing multi-tenant authentication and authorization flows • Lessons learned from MCP vulnerabilities and Azure template exposures If you’re a security researcher, CISO, or technical leader interested in advanced detection techniques and evolving best practices, see how MSRC is raising the bar for proactive defense. Read the full blog post here: msft.it/6011tzx2V
1
10
36
6,828
4 Nov 2025
Check out the villages at BlueHat Asia!!!!!
At BlueHat Asia, we have 6 unique security villages to explore, each packed with hands-on opportunities and practical learnings. Check out the attached video to learn more: ➤ Phishing Village: Sharpen your detection and response skills with live CTFs, quizzes, and AI-driven simulations. ➤ MSRC Village: Engage with researchers, enter the raffle contest, and tackle CTF challenges of varying difficulty. ➤ AI Security Village: Dive into the intersection of cybersecurity and AI. Defend against and simulate AI-powered attacks while competing for leaderboard glory. ➤ AppSec Village: Strengthen your application security expertise with hands-on modules for every skill level, from pentesters to blue teamers. ➤ Forensics & Attack Village: Explore digital forensics across platforms with quizzes, CTFs, and interactive demos. Experience an innovative CTF where you trace adversaries, map exploit chains, and learn practical graph analysis techniques. ➤ IoT Village: Step into the world of IoT and drone security, where physical and digital threats converge. Solve CTFs that test your skills in real-world scenarios. #BlueHatAsia
2
164
22 Oct 2025
Woooooo!!!!!! Way to go @TzahPahima 🔥
We’re excited to announce our next BlueHat Asia speaker, Tzah Pahima (@TzahPahima), an independent Cloud Security Researcher renowned for uncovering and exploiting vulnerabilities in the cloud ecosystem. Tzah’s expertise spans vulnerability research and web security, making him a leading voice in advancing secure cloud practices. With a background that includes five years of service in an Israeli military intelligence unit, Tzah brings a unique perspective and deep technical insight to the field. Expect an engaging session packed with real-world examples, cutting-edge techniques, and actionable strategies for strengthening cloud security. #BlueHatAsia
1
147
Wendy retweeted
We’re excited to announce our next BlueHat Asia speakers: Brian McNulty (@brianjmcnulty) and Cameron Vincent (@SecretlyHidden1)! Cameron is a Senior Security Researcher at Microsoft, specializing in vulnerabilities and mitigation within MSRC. From reproducing bug reports to variant hunting, Cameron has spent the last decade identifying and mitigating trends to protect the Microsoft ecosystem. His research focuses on authentication and authorization vulnerabilities, an area he’s been passionate about for over 10 years. Brian began making a name for himself through Meta’s bug bounty program and is just getting started. Currently a student at the University of Michigan, Brian has proven his skills as a 2025 MSRC intern and as a top player in the bug bounty world, ranking in Meta’s top 5 multiple times. He’s also working toward his master’s in computer science, continuing to push boundaries in security research. Their upcoming talk will take you inside the MSRC Vulnerabilities & Mitigations team, exploring how variant hunting and deep issue analysis help secure the Microsoft ecosystem. #BlueHatAsia
4
12
3,172
18 Sep 2025
Great read! Well done, @_dirkjan
Thank you, @_dirkjan, for partnering with the MSRC to protect customers. Your work demonstrates the power of coordinated vulnerability disclosure and community collaboration.
3
624
15 Sep 2025
If you have not signed up, please do!
Join MSRC on September 17 for a 30-minute conversation with Pushkar Saraf, Director of Security, Microsoft AI. He’ll share how he approaches security research, from spotting opportunities to the techniques and workflows that drive real-world results. Expect practical insights, lessons from the field, and a moderated Q&A to dive deeper into the discussion. Whether you're new to security research or looking to sharpen your skills, this session offers a look into the workflows, challenges, and creative problem-solving that drive impactful findings. Register now: msft.it/6012s9gvE #ZeroDayQuest
212
15 Sep 2025
Well deserved, @HaifeiLi
13 Sep 2025
Look what I just received. Thank you @msftsecresponse for delivering the MVR 2025 swag box to me. 😊
1
3
425
8 Sep 2025
Who is joining us!!!??? #zerodayquest #MSRC #SecurityChats #AI These chats are super informative and fun and we open it up for Q&A so you all can feel free to ask questions!
Join MSRC on September 17 for a 30-minute conversation with Pushkar Saraf, Director of Security, Microsoft AI. He’ll share how he approaches security research, from spotting opportunities to the techniques and workflows that drive real-world results. Expect practical insights, lessons from the field, and a moderated Q&A to dive deeper into the discussion. Whether you're new to security research or looking to sharpen your skills, this session offers a look into the workflows, challenges, and creative problem-solving that drive impactful findings. Register now: msft.it/6012s9gvE #ZeroDayQuest
186
22 Aug 2025
Who is joining me for this? #zerodayquest #research #MSRC
Are you a security researcher hoping to qualify for Zero Day Quest or looking to level up your research game? MSRC invites you to a two-part series of candid conversations with our internal researchers, designed to help you sharpen your skills and stay inspired during the Research Challenge. In each session, we’ll explore how security researchers approach their work, from identifying new opportunities to navigating challenges and solving complex problems. Whether you're just starting out or deep into your research journey, you'll gain practical insights and lessons learned. Featured speakers: Estevam Arantes (@Es7evam), Security Software Engineer, Microsoft Santiago Zanella-Béguelin (@xEFFFFFFF), Principal Researcher, Microsoft Mark your calendars: Security Chats: Inside the Research Process 🗓️ Part 1: August 26, 2025 | 10–11 AM PT 🗓️ Part 2: September 3, 2025 | 10–11 AM PT Register now: microsoft.eventsair.com/msrc… #ZeroDayQuest
1
2
234