Wendy

2.3K posts

Wendy banner
Wendy

Wendy

@ZenOneSec

Security @ Microsoft & BlueHat Podcast Co Host

Endor Bergabung Şubat 2014
1.7K Mengikuti1.5K Pengikut
Tom Gallagher
Tom Gallagher@secbughunter·
@dhiralpatel94 @msftsecresponse I can't believe the team made these and secretly planted them at the event. A real‑world Easter egg. Getting handed one as I started opening remarks was surprising, slightly embarrassing, and not in my threat model. 😂 Fun start to #ZeroDayQuest
English
1
0
2
117
Wendy
Wendy@ZenOneSec·
Super excited about this!
Microsoft Security Response Center@msftsecresponse

The global security research community plays a critical role in protecting Microsoft customers. As Tom Gallagher (@secbughunter), VP of Engineering at MSRC, shares in today’s announcement, we’re evolving how researcher impact is recognized. Starting with the July 2026 Most Valuable Researcher (MVR) leaderboard, rankings will be based on bounty award amounts, providing a consistent signal that aligns recognition with vulnerability severity and security outcomes. We’re also introducing honorable mentions to recognize all researchers who submit valid vulnerability reports, independent of ranking. Read the full announcement for more details: msft.it/6013Q3zlv

English
0
0
2
167
Wendy me-retweet
Microsoft Security Response Center
Microsoft Security Response Center@msftsecresponse·
In our latest blog, Cameron Vincent (@SecretlyHidden1), Senior Security Researcher at MSRC, features the work of MSRC intern and security researcher, Brian McNulty (@brianjmcnulty), who uncovered 22+ critical vulnerabilities in just two months. Learn how the MSRC team leverages automation and tools like IMPOSTR to identify risky multi-tenant apps, why robust authentication and authorization are essential, and how new protocols like Model Context Protocol (MCP) are shaping the future of secure AI integration. This blog covers: • Real-world attack scenarios and variant hunting strategies • Securing multi-tenant authentication and authorization flows • Lessons learned from MCP vulnerabilities and Azure template exposures If you’re a security researcher, CISO, or technical leader interested in advanced detection techniques and evolving best practices, see how MSRC is raising the bar for proactive defense. Read the full blog post here: msft.it/6011tzx2V
Microsoft Security Response Center tweet media
English
1
10
37
6.7K
Wendy
Wendy@ZenOneSec·
Woooooo!!!!!! Way to go @TzahPahima 🔥
Microsoft BlueHat@MSFTBlueHat

We’re excited to announce our next BlueHat Asia speaker, Tzah Pahima (@TzahPahima), an independent Cloud Security Researcher renowned for uncovering and exploiting vulnerabilities in the cloud ecosystem. Tzah’s expertise spans vulnerability research and web security, making him a leading voice in advancing secure cloud practices. With a background that includes five years of service in an Israeli military intelligence unit, Tzah brings a unique perspective and deep technical insight to the field. Expect an engaging session packed with real-world examples, cutting-edge techniques, and actionable strategies for strengthening cloud security. #BlueHatAsia

English
0
0
1
141
Wendy me-retweet
Microsoft BlueHat
Microsoft BlueHat@MSFTBlueHat·
We’re excited to announce our next BlueHat Asia speakers: Brian McNulty (@brianjmcnulty) and Cameron Vincent (@SecretlyHidden1)! Cameron is a Senior Security Researcher at Microsoft, specializing in vulnerabilities and mitigation within MSRC. From reproducing bug reports to variant hunting, Cameron has spent the last decade identifying and mitigating trends to protect the Microsoft ecosystem. His research focuses on authentication and authorization vulnerabilities, an area he’s been passionate about for over 10 years. Brian began making a name for himself through Meta’s bug bounty program and is just getting started. Currently a student at the University of Michigan, Brian has proven his skills as a 2025 MSRC intern and as a top player in the bug bounty world, ranking in Meta’s top 5 multiple times. He’s also working toward his master’s in computer science, continuing to push boundaries in security research. Their upcoming talk will take you inside the MSRC Vulnerabilities & Mitigations team, exploring how variant hunting and deep issue analysis help secure the Microsoft ecosystem. #BlueHatAsia
Microsoft BlueHat tweet mediaMicrosoft BlueHat tweet media
English
0
4
12
3.1K
Wendy me-retweet
Microsoft Security Response Center
Microsoft Security Response Center@msftsecresponse·
Microsoft’s Zero Day Quest is back and bigger than ever. Last year, we launched the largest public hacking event in history, and the global security community responded with incredible energy and expertise. We’re increasing our commitment with up to $5 million in total bounty awards for high-impact research in cloud and AI security. Learn more about how you can participate in the Zero Day Quest Research Challenge and qualify for our exclusive Live Hacking Event in Redmond: msft.it/6010szF6y #ZeroDayQuest
Microsoft Security Response Center tweet media
English
0
32
85
22K
Wendy me-retweet
Microsoft Security Response Center
Microsoft Security Response Center@msftsecresponse·
At @defcon, the MSRC team had a great time connecting with the security community and cheering on Microsoft employees, MVRs, and other Microsoft security researchers as they shared their expertise through presentations and hands-on collaboration. #DEFCON #DEFCON33
English
2
4
24
5.5K
Wendy me-retweet
Microsoft Security Response Center
Microsoft Security Response Center@msftsecresponse·
One week ago, we came together at the MSRC Researcher Celebration during Black Hat to honor the incredible community that helps keep Microsoft secure. From meaningful conversations to Clippy through the decades on display, it was a night to connect and celebrate your contributions. Thank you to everyone who joined us. You’re the reason we do what we do. #BHUS
English
1
6
22
7.7K