I like to break stuff / Security at @Microsoft / Sometimes I play CTFs with @GaneshICMC / Personal Account ⟦PT/EN⟧

Joined June 2018
3 Photos and videos
Jan 23
My 5th M365 Copilot CVE just got released yesterday (CVE-2026-24307), some forums are mentioning it as "Reprompt". That's a different vuln and I have nothing to do with it. This was the coolest one so far, hopefully I'll be able to talk about it publicly soon :)
2
289
22 Aug 2025
I'll be talking to MSRC folks about some of my research process and maybe some of the vulns I've found, come ask questions!
Are you a security researcher hoping to qualify for Zero Day Quest or looking to level up your research game? MSRC invites you to a two-part series of candid conversations with our internal researchers, designed to help you sharpen your skills and stay inspired during the Research Challenge. In each session, we’ll explore how security researchers approach their work, from identifying new opportunities to navigating challenges and solving complex problems. Whether you're just starting out or deep into your research journey, you'll gain practical insights and lessons learned. Featured speakers: Estevam Arantes (@Es7evam), Security Software Engineer, Microsoft Santiago Zanella-Béguelin (@xEFFFFFFF), Principal Researcher, Microsoft Mark your calendars: Security Chats: Inside the Research Process 🗓️ Part 1: August 26, 2025 | 10–11 AM PT 🗓️ Part 2: September 3, 2025 | 10–11 AM PT Register now: microsoft.eventsair.com/msrc… #ZeroDayQuest
6
493
Estevam retweeted
Great talking with the amazing Microsoft Office Security team. #MSFTBlackHat
3
25
3,964
Exciting News! 📢 We're boosting our Microsoft 365 Insider Bounty Program, increasing awards up to $30,000 and expanding the scope of eligible vulnerabilities in our Office products and services. Find out more in our blog: msft.it/6019cr7yt
13
30
21,821
Estevam retweeted
And here's the link to apply as a member of the team (as an engineer). google.com/about/careers/app…

Google's Product Security Team (my broader team!) is hiring in Brazil! Here's the link for the Manager we want to hire there to start the team! google.com/about/careers/app…
12
26
7,368
30 Aug 2023
The Office Security team is hiring! Feel free to reach out if you have any questions. jobs.careers.microsoft.com/g…

265
Stop on by the Office Insider Bug Bounty Program and check out the new attack scenario for Microsoft Defender Application Guard for Office with awards up to $15,000! microsoft.com/en-us/msrc/bou…
1
9
24
8 Aug 2022
Looking forward to seeing some nice research😃
Hope everyone enjoys tomorrow's Office symbol release. Thanks to everyone inside of Microsoft for making this happen. It was a bit of work. We look forward to enabling high quality Office research. 😀 msrc-blog.microsoft.com/2022…
7 Feb 2022

1
7 Dec 2021
After almost 2 years waiting for my visa, today I finally had my first day as a Security Software Engineer at Microsoft! Happy to be here :)
10
Estevam retweeted
Urna eletrônica: O Teste Público de Segurança 2021 chegou ao fim. Os pesquisadores descobriram algumas vulnerabilidades 'interessantes' na urna, que deverão ser corrigidas pelo TSE até maio. Acompanhe 👇
30
314
1,523
Estevam retweeted
18 Oct 2021
Wanna learn heap exploitation in the post-safe-linking era? A new release of how2heap is here to help! Check it out! github.com/shellphish/how2he…
1
121
458
6 Oct 2021
Para quem tem interesse, vale a leitura técnica em urnaeletronica.info

Internet BR celebra "abertura" do código-fonte da urna e ignora que inspeção: - É reservada a certas instituições - Acontece apenas em BSB - É restrita à leitura do código (milhões de linhas) - Não cobre alterações posteriores - Acontece assim faz tempo x.com/TSEjusbr/status/144507…
Estevam retweeted
Hello Everyone, Need the Cybersecurity community's help. We need to vote so Twitch has a Cybersecurity category, so we stop using "science and technology". Please enter here and vote: twitch.uservoice.com/forums/… @NahamSec @thecybermentor @stokfredrik Would U RT please? Thanks!!!

2
40
67
3 Aug 2021
Not sure if this is about fuzzing or virology
what doesn't kill you mutates & will try again.
1
Estevam retweeted
30 May 2021
#Pwn2Win 2021 is over! Thanks to all the Brazilian teams! Congratulations to top3 Brazil ! \o/ Top 1 - @GaneshICMC Top 2 - @fireshellst Top 3 - #ShingekiNoChikungunya
1
15
45
Estevam retweeted
9 Mar 2021
Inspired by @TinkerSec, I'll tweet out a "hack job" I recently did. I rarely pentest companies, I've always been a blue teamer. The pentest gigs I do are generally favors to other blue team friends to teach them. My rate was $50/h which is much lower than what I typically charge.
23
267
1,088
7 Aug 2020
RT @hacknotcrime: What most people think hacking is versus what hacking really is.
1,714
Estevam retweeted
1 Jul 2020
A etapa do nosso babaca preferido tem campeão!! Parabéns pela sua vitória e classificação, @es7evam. Exploitou essa etapa com sucesso. . E você? Está esperando o que para ser um dos campeões do maior campeonato estilo CTF da América Latina? #FiqueEmCasa #MasFiqueOwnando
3
18