We are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit microsoft.com/en-us/msrc.

Joined February 2010
354 Photos and videos
Security updates for June 2026 are now available. Details are here: msft.it/6018SZEg0 #PatchTuesday
4
14
28
15,759
The BlueHat Asia Call for Papers closes June 15. If you’ve been considering submitting, now’s the time: aka.ms/BlueHatAsiaCFP

📣The BlueHat Asia Call for Papers is now open! 📣 BlueHat brings together security researchers and defenders to exchange ideas, experiences, and best practices. We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and related areas across the security landscape. 📍Singapore | September 17–18, 2026 🗓️CFP deadline: June 15, 2026 Submit your paper now: aka.ms/BlueHatAsiaCFP
4
6
21
17,211
Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community, and will continue to take your feedback seriously. To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate. We recognize the work that goes into researching and submitting a vulnerability. We are committed to approaching every interaction with transparency, clear communication, and professionalism. We continue to believe strongly in Coordinated Vulnerability Disclosure as the foundation for protecting customers and improving our products. Each year we process a high volume of vulnerability reports. That volume continues to grow and will continue with the rise of AI-enabled research. We acknowledge that some interactions have fallen short and are working to learn from them. Many of us have experience on both sides of this work, as researchers reporting vulnerabilities and as responders triaging and assessing them. That perspective informs how we approach this feedback and the importance we place on getting it right, particularly as the volume and complexity of research continues to grow. The security community plays a vital role in helping us protect customers. We are committed to maintaining a constructive and respectful relationship and growing together. We know that, given the nature of this work, there will at times be misunderstandings. We remain committed to engaging in good faith and to providing a respectful and professional experience for all researchers, regardless of past interactions.
Community note
Contrary to this claim, Microsoft previously threatened legal action via its Digital Crimes Unit against researcher Nightmare Eclipse for publishing unpatched vulnerabilities. pcmag.com/news/microsoft…
319
106
483
582,663
Microsoft Security Response Center retweeted
BlueHat Asia is heading to Singapore on September 17–18! 👉Apply now for your chance to join us: aka.ms/bluehatreg Applications close July 17. #BlueHat
1
2
9
6,159
Less than one month to go ⏳ The BlueHat Asia Call for Papers closes June 15. Don't miss your chance to share your research! Submit your talk today: aka.ms/BlueHatAsiaCFP

📣The BlueHat Asia Call for Papers is now open! 📣 BlueHat brings together security researchers and defenders to exchange ideas, experiences, and best practices. We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and related areas across the security landscape. 📍Singapore | September 17–18, 2026 🗓️CFP deadline: June 15, 2026 Submit your paper now: aka.ms/BlueHatAsiaCFP
2
4
10
8,450
Security updates for May 2026 are now available. Details are here: msft.it/6018SZEg0 This month’s release reflects a broader shift across the industry, with advances in automation, increased researcher participation, and the growing use of AI accelerating the discovery of vulnerabilities. As a result, security updates may continue to trend larger over time, while the process behind how Microsoft validates, prioritizes, and delivers fixes remains consistent. As discovery speeds up, the fundamentals matter more than ever. Stay current on patches, reduce exposure, strengthen identity protections, and invest in detection and response. Learn more in our blog post by Tom Gallagher, VP of Engineering, MSRC: msft.it/6011vP78L
1
20
37
26,222
Update to the Windows Insider Preview bounty program: General Awards for Elevation of Privilege and Information Disclosure are now split by finishing privilege, with award ranges increasing to $1,000–$8,000. This change is designed to better align rewards with the impact of reported vulnerabilities. Learn more on the Windows Insider Preview bounty page: msft.it/6018v3QZI
1
8
26
6,005
Microsoft Security Response Center retweeted
Day 2 at BlueHat 2026 wrapped with new learnings, fresh perspectives, and continued discussions across the security community. From Mark Russinvoch’s keynote to deep technical sessions, the focus stayed clear: advancing security, together. Take a look at some of the highlights from Day 2 ⬇️ #BlueHat
1
1
6
2,812
Microsoft Security Response Center retweeted
Day 2 is underway at BlueHat. Here’s a look back at Day 1. A strong start, with the security community coming together to connect, share insights, and tackle real-world challenges. Watch the highlights ⬇️ #BlueHat
2
9
2,842
RT @MSFTBlueHat: Thank you to everyone who joined us for day 1 of BlueHat 2026! We kicked things off with opening remarks from Tom Gallagh…
1
433
Microsoft Security Response Center retweeted
Thank you to our BlueHat speakers who joined us for the welcome reception this evening. We are looking forward to welcoming everyone tomorrow for the first day of BlueHat, along with the presentations and conversations that bring this community together. #BlueHat
3
10
3,061
We’ve updated the Microsoft 365 Insider Builds on Windows Bounty Program to better recognize impactful research and improve the submission experience for our community. What’s new: • Added Information Disclosure as an eligible impact category • Increased awards for Security Feature Bypass to align with top General Award levels • Introduced three new high‑impact scenarios, with awards of $30K, $20K, and $20K • Maintained the $30K award for unauthenticated, non‑sandboxed code execution with no user interaction These updates reflect feedback from researchers and help ensure the program continues to reward high‑impact research while strengthening protections for customers. Learn more: microsoft.com/en-us/msrc/bou…
4
31
10,220
At BlueHat Asia, Cameron Vincent (@SecretlyHidden1), Senior Security Researcher, MSRC and Brian McNulty, MSRC Summer Intern, walk through real-world variant hunting inside MSRC, including: • Common multi-tenant authorization pitfalls • What not to trust in JWT claims • How tools like Impostor help uncover risk at scale Watch the full session and explore the slides to dive deeper into the research and practical guidance: youtube.com/watch?v=LykXwP4k… Want to speak at BlueHat Asia? Submit your talk by June 15: aka.ms/BlueHatAsiaCFP
4
21
5,178
Microsoft Security Response Center retweeted
Apr 24
Have a lovely night connecting with MSRC team and MVRs, thanks @msftsecresponse for inviting me to attend Black Hat Asia and MSRC Researcher Celebration😊”trust me, we all love MSRC” — via Yuki Chen
Thank you to everyone who joined us for the MSRC Researcher Celebration at Black Hat Asia. It was great to connect with so many in the community and spend time sharing ideas and conversations. We appreciate the collaboration that drives this work forward and look forward to what we’ll build together next.
1
3
28
6,739
Thank you to everyone who joined us for the MSRC Researcher Celebration at Black Hat Asia. It was great to connect with so many in the community and spend time sharing ideas and conversations. We appreciate the collaboration that drives this work forward and look forward to what we’ll build together next.
2
2
35
16,559
Collaboration with the security research community continues to strengthen protection for customers. Read how Harun's journey from his first report to Most Valuable Researcher highlights the real-world impact of cloud security research and coordinated vulnerability disclosure: msft.it/6012vE1zy
12
3
22
3,425
New research ready to share? Submit to BlueHat Asia by June 15: aka.ms/BlueHatAsiaCFP

📣The BlueHat Asia Call for Papers is now open! 📣 BlueHat brings together security researchers and defenders to exchange ideas, experiences, and best practices. We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and related areas across the security landscape. 📍Singapore | September 17–18, 2026 🗓️CFP deadline: June 15, 2026 Submit your paper now: aka.ms/BlueHatAsiaCFP
8
2
16
14,421