Joined October 2011
24 Photos and videos
Stephanie Calabrese retweeted
🗓️ Mark your calendars 🗓️ BlueHat is headed to Singapore, September 17–18. Call for Papers and registration announcements coming soon. 👀

ALT Save the date: BlueHat Asia 2026

3
2
9
2,524
This will be our first Researcher Celebration at Black Hat Europe! I look forward to catching up with our researcher community! If you will be in town, please apply to attend!
Join the Microsoft Security Response Center (MSRC) for our Researcher Celebration at Black Hat Europe on Wednesday, December 10, from 4:30–9:00 PM. This event honors the contributions of the global security research community. Connect with peers, celebrate achievements, and enjoy networking with researchers from around the world. Apply to attend now: microsoft.eventsair.com/msrc… #BHEU
4
387
#ZeroDayQuest is everything we have hoped for so far - and it has just begun!
Kicking off #ZeroDayQuest with the ladies of @msftsecresponse
8
359
Stephanie Calabrese retweeted
A big thank you to everyone who joined us for the MSRC @Nullcon Goa speaker dinner. We hope everyone enjoyed connecting with so many passionate members of the security community. The security community thrives on collaboration, and we’re grateful to be part of it. #NullconGoa2025 #nullcon
2
26
4,192
Stephanie Calabrese retweeted
Cameron Vincent @SecretlyHidden1, Security Researcher at Microsoft, gave a talk about IDOR vulnerabilities to a packed room at @nullcon #Goa. Cameron discussed how broken access control has been the top problem across the ecosystem for a while. Camerons research into IDOR vulnerabilities was manual, without extensions or automation, although he recommends using Burp Suite, which = the golden tool. #NullconGoa2025 #Nullcon
4
29
5,142
This is so exciting! Make sure to register for the AI Red Team Training (aka.ms/AIRedTeamTraining) and submit your Cloud & AI bounties for multiplied rewards! @ram_ssk @secbughunter @eckert_madeline @RebeccaPattee

As part of our Secure Future Initiative and to further the security of our customers, ourselves, and the world, today we are introducing the most transparent security research event in history: The Zero Day Quest. This new hacking event will be the largest of its kind, with an additional $4 million in potential awards for research into high-impact areas, specifically cloud and AI. Starting today, the quest kicks off with a research challenge where vulnerability submissions in targeted scenarios are eligible for multiplied bounty awards. Submissions can also qualify researchers for a spot in the onsite hacking event in Redmond, WA, in 2025. Learn more in our blog post:  msrc.microsoft.com/blog/2024… #ZeroDayQuest
3
10
942
One of my fave #BlueHat pics ever. With icons @ram_ssk, @markrussinovich, and @michael_howard. #InMyBlueHatEra
1
1
18
1,471
Stephanie Calabrese retweeted
Why do we have to vote every 4 years? Why does Taylor Swift not simply assume the monopoly of violence and enact herself the undisputed sovereign and through her vassals exercise regulatory administration and enforcement actions? Then, we will have libraries with water slides.
13
30
281
29,235
Two of the most epic speakers I know! So inspiring!
Today at the Microsoft STRIKE event: “STRIKE Live: Practical AI Safety and Security,” Eric Douglas, CVP, Security Research, Microsoft, gave the opening remarks, and Yonatan Zunger, CVP, AI Safety and Security, Microsoft, delivered the keynote to a large group of Microsoft engineers. They emphasized that safety must become as fundamental to our work as breathing. So, what are the basic principles of safety engineering? 1. Know the ways your system might fail as intimately as the ways your system should work: • Brainstorm failure scenarios and keep that list as fresh as your success scenarios. • What you don’t know can hurt you – so use many eyes and plan for surprises. 2. For each scenario, have a plan: • Eliminate it. • Reduce its severity or frequency. • Give users a way to solve it themselves. • Have a response plan for when things go wrong. How do you do that brainstorming? Eric and Yonatan recommend a three-pronged approach: • System-first: What are the components? What happens if each one fails? What if it gets bad input? And the components include the users! • Actor-first: What might someone want to achieve using this software? Under what circumstances are they using it? • Target-first: Who might be affected by someone using this software? What might make them more or less vulnerable? How would they be able to respond?
2
383
Stephanie Calabrese retweeted
Today at the Microsoft STRIKE event: “STRIKE Live: Practical AI Safety and Security,” Eric Douglas, CVP, Security Research, Microsoft, gave the opening remarks, and Yonatan Zunger, CVP, AI Safety and Security, Microsoft, delivered the keynote to a large group of Microsoft engineers. They emphasized that safety must become as fundamental to our work as breathing. So, what are the basic principles of safety engineering? 1. Know the ways your system might fail as intimately as the ways your system should work: • Brainstorm failure scenarios and keep that list as fresh as your success scenarios. • What you don’t know can hurt you – so use many eyes and plan for surprises. 2. For each scenario, have a plan: • Eliminate it. • Reduce its severity or frequency. • Give users a way to solve it themselves. • Have a response plan for when things go wrong. How do you do that brainstorming? Eric and Yonatan recommend a three-pronged approach: • System-first: What are the components? What happens if each one fails? What if it gets bad input? And the components include the users! • Actor-first: What might someone want to achieve using this software? Under what circumstances are they using it? • Target-first: Who might be affected by someone using this software? What might make them more or less vulnerable? How would they be able to respond?
4
24
5,157
It is official. My life is complete! Thanks, @shenanigans_us! If you see me, I have stickers!!!
1
4
25
996
Excited to kick off summer camp!!! @secbughunter @sherrod_im @msftsecresponse #MSFTBlackHat
6
474
The incomparable @sherrod_im presenting at The Diana Initiative! Always mindblowing!! @msftsecresponse #MSFTBlackHat
2
5
15
1,670
Stephanie Calabrese retweeted
17 May 2024
Enjoying day 2 of #BluehatIndia
4
6
31
3,305
Stephanie Calabrese retweeted
1
3
21
8,253
#BlueHatIndia has officially kicked off. @secbughunter and @JohnLaTwC killed it on stage. @MSFTBlueHat
1
6
19
2,536
I should be asleep, but I am too excited!!! Amazing speakers - I can't wait for the first BlueHat India! See you all soon!
We hosted a pre-BlueHat India welcome reception this evening, providing an opportunity for our speakers, MSRC MVRs, and Microsoft team members to connect. We are thankful to our speakers and MVRs for their role in making #BlueHatIndia a success.
5
450