Thank you @msftsecresponse for the amazing swag box!
Grateful for the collaboration in making
Microsoft products safer and protecting millions of users. 💙🔐
🎉 Excited to share an amazing milestone! I received my highest bounty ever from a security report that required a lot of learning, effort, and dedication. Grateful to everyone who made this journey possible! 🚀
@msftsecresponse#bugbounty#bugbountytips
Hackers,
To make our pricing fairer worldwide, we’re trying out localized pricing.
We’re starting with Brazil 🇧🇷, with Individual plan prices dropping by about 50%.
💸 Monthly: ~110 BRL → 55 BRL
💸 Yearly: ~1,100 BRL → 550 BRL
Which country should we do next?…
Are you a security researcher hoping to qualify for Zero Day Quest or looking to level up your research game? MSRC invites you to a two-part series of candid conversations with our internal researchers, designed to help you sharpen your skills and stay inspired during the…
Over the past year, the Microsoft Bounty Program distributed $17 million to 344 security researchers from 59 countries—the highest total bounty awarded in the program’s history. Thank you to our global security researcher community for helping us protect customers and the world.…
The MSRC team and I are excited up to connect and learn from security researchers and the community at Black Hat & DEF CON this week! If you spot me, I might have a shirt with your name on it. #blackhat2025 #blackhat#defcon@msftsecresponse
Microsoft’s Zero Day Quest is back and bigger than ever. Last year, we launched the largest public hacking event in history, and the global security community responded with incredible energy and expertise. We’re increasing our commitment with up to $5 million in total bounty…
Attention security researchers! 📣
The Microsoft .NET Bounty Program just got a major upgrade, with rewards now up to $40,000 for critical vulnerabilities in .NET and ASP. NET Core (including Blazor & Aspire).
Learn more in our blog post: msrc.microsoft.com/blog/2025/07/.…
Update: Microsoft has released updated analysis of Storm-2603 and Warlock ransomware. Customers should apply the on-premises SharePoint Server security updates immediately and follow the detailed mitigation guidance in our blog: msft.it/6040s130q
Update: Microsoft has released updated analysis of Storm-2603 and Warlock ransomware. Customers should apply the on-premises SharePoint Server security updates immediately and follow the detailed mitigation guidance in our blog: msft.it/6040s130q
Microsoft has released security updates for all supported on-premises SharePoint Server versions. Cloud-hosted SharePoint is not affected.
We strongly urge customers to apply these updates immediately to protect against active exploitation.
Our latest blog also shares insights…
Microsoft has released security updates for all supported on-premises SharePoint Server versions. Cloud-hosted SharePoint is not affected.
We strongly urge customers to apply these updates immediately to protect against active exploitation.
Our latest blog also shares insights…
Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. These vulnerabilities apply to on-premises SharePoint Servers only. Customers should apply these updates immediately to…
Update on CVE-2025-53770: Microsoft has released a security update for SharePoint Subscription Edition to mitigate active attacks targeting on-premises servers. SharePoint Online is not affected. Customers should apply the update immediately.
We are actively working on updates…
Our previously published Most Valuable Researchers (MVR) leaderboard contained inaccuracies due to technical issues on our end. We apologize for the error and have since resolved the issue. We’re now sharing a fully refreshed and accurate leaderboard.
The Microsoft Researcher…
491 Followers 331 FollowingCTFer@Dubhe / 2024 & 2025 MSRC MVR / Windows security / Web security/ Red Teamer / BlackHat USA
Graduate for Ph.D. in Fudan University
340 Followers 4K FollowingCrypto Enthusiast & Blockchain Researcher | Building the Future, One Block at a Time
Relentlessly Learning | Deep into Decentralization | Grinding 🗿❤️🥇
491 Followers 331 FollowingCTFer@Dubhe / 2024 & 2025 MSRC MVR / Windows security / Web security/ Red Teamer / BlackHat USA
Graduate for Ph.D. in Fudan University
5K Followers 181 FollowingSenior Security Researcher @akamai - Malicious Group - SRT - DoD researcher of the year 2022 - Top 10 web attacks 2023 - CRTO - MSRC Top 75 in Q1/Q2 2025
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
7K Followers 597 FollowingHacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg
2K Followers 31 FollowingYour twice-monthly Azure Security podcast. News and security chats with special guests. Hosted by @marksimos, @_sarahyo, @michael_howard and @Cyber_batgirl.
1K Followers 654 FollowingJeff Jones, Sr Director, Microsoft. Communicator. Security guy. Digital Dad. Soccer Dad, Investor, Reader, Writer, Poker player. Co-host of https://t.co/X1UoUFjVbG
29K Followers 206 FollowingHacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
10K Followers 6 FollowingBringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM
229K Followers 931 FollowingResearcher and a best-selling author. Keynote talks at RSA, Black Hat & DEF CON. TED Speaker. Chief Research Officer at Sensofusion.
83K Followers 16 FollowingTrend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
43K Followers 899 FollowingCo-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
8K Followers 151 FollowingFor contact in the security community. NOTE: All the tweets are totally my personal opinions, not about any of my current employer stuff.
36K Followers 7K FollowingWeird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
53K Followers 616 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.