Wendy
2.3K posts

Wendy
@ZenOneSec
Security @ Microsoft & BlueHat Podcast Co Host







Day 1 of the Zero Day Quest Onsite Hacking Event is in the books and we’ve kicked off Day 2. We welcomed top security researchers from around the world to Microsoft’s Redmond campus for a day of live hacking, collaboration, and connection. Researchers worked side-by-side with Microsoft engineers and product teams to identify vulnerabilities across our AI and cloud platforms. Lots of amazing reports and discussions flowed throughout the day with MSRC, product teams, and the researchers themselves all driving security forward together. We wrapped the day with a Seattle Kraken vs. Tampa Bay Lightning game in Seattle (tough loss, but the vibes were strong!). We’re incredibly grateful to the security researcher community. Your work makes a real impact in helping protect customers. #ZeroDayQuest

Today, we’re welcoming top security researchers from around the world to Microsoft’s Redmond campus for the first official day of the Zero Day Quest Onsite Hacking Event. They’ll collaborate with Microsoft engineers and product teams to uncover vulnerabilities across our AI and cloud platforms over the next two days. We’re thankful for the security researcher community and the impact their work has in helping protect customers. #ZeroDayQuest

We’re excited to welcome some of the world’s top security researchers to Zero Day Quest 2026 🎉 We kicked off the onsite hacking event with bowling, followed by dinner and drinks with incredible views. It’s the start of a full week of security research, collaboration with Microsoft teams, and social events including a Kraken hockey game, a brunch cruise, and more. We’re grateful to every researcher who qualified and joined us in person, as well as those participating remotely. Their work and partnership with Microsoft help protect customers and communities around the world. #ZeroDayQuest

The global security research community plays a critical role in protecting Microsoft customers. As Tom Gallagher (@secbughunter), VP of Engineering at MSRC, shares in today’s announcement, we’re evolving how researcher impact is recognized. Starting with the July 2026 Most Valuable Researcher (MVR) leaderboard, rankings will be based on bounty award amounts, providing a consistent signal that aligns recognition with vulnerability severity and security outcomes. We’re also introducing honorable mentions to recognize all researchers who submit valid vulnerability reports, independent of ranking. Read the full announcement for more details: msft.it/6013Q3zlv



At BlueHat Asia, we have 6 unique security villages to explore, each packed with hands-on opportunities and practical learnings. Check out the attached video to learn more: ➤ Phishing Village: Sharpen your detection and response skills with live CTFs, quizzes, and AI-driven simulations. ➤ MSRC Village: Engage with researchers, enter the raffle contest, and tackle CTF challenges of varying difficulty. ➤ AI Security Village: Dive into the intersection of cybersecurity and AI. Defend against and simulate AI-powered attacks while competing for leaderboard glory. ➤ AppSec Village: Strengthen your application security expertise with hands-on modules for every skill level, from pentesters to blue teamers. ➤ Forensics & Attack Village: Explore digital forensics across platforms with quizzes, CTFs, and interactive demos. Experience an innovative CTF where you trace adversaries, map exploit chains, and learn practical graph analysis techniques. ➤ IoT Village: Step into the world of IoT and drone security, where physical and digital threats converge. Solve CTFs that test your skills in real-world scenarios. #BlueHatAsia

We’re excited to announce our next BlueHat Asia speaker, Tzah Pahima (@TzahPahima), an independent Cloud Security Researcher renowned for uncovering and exploiting vulnerabilities in the cloud ecosystem. Tzah’s expertise spans vulnerability research and web security, making him a leading voice in advancing secure cloud practices. With a background that includes five years of service in an Israeli military intelligence unit, Tzah brings a unique perspective and deep technical insight to the field. Expect an engaging session packed with real-world examples, cutting-edge techniques, and actionable strategies for strengthening cloud security. #BlueHatAsia




Join MSRC on September 17 for a 30-minute conversation with Pushkar Saraf, Director of Security, Microsoft AI. He’ll share how he approaches security research, from spotting opportunities to the techniques and workflows that drive real-world results. Expect practical insights, lessons from the field, and a moderated Q&A to dive deeper into the discussion. Whether you're new to security research or looking to sharpen your skills, this session offers a look into the workflows, challenges, and creative problem-solving that drive impactful findings. Register now: msft.it/6012s9gvE #ZeroDayQuest

Join MSRC on September 17 for a 30-minute conversation with Pushkar Saraf, Director of Security, Microsoft AI. He’ll share how he approaches security research, from spotting opportunities to the techniques and workflows that drive real-world results. Expect practical insights, lessons from the field, and a moderated Q&A to dive deeper into the discussion. Whether you're new to security research or looking to sharpen your skills, this session offers a look into the workflows, challenges, and creative problem-solving that drive impactful findings. Register now: msft.it/6012s9gvE #ZeroDayQuest

Are you a security researcher hoping to qualify for Zero Day Quest or looking to level up your research game? MSRC invites you to a two-part series of candid conversations with our internal researchers, designed to help you sharpen your skills and stay inspired during the Research Challenge. In each session, we’ll explore how security researchers approach their work, from identifying new opportunities to navigating challenges and solving complex problems. Whether you're just starting out or deep into your research journey, you'll gain practical insights and lessons learned. Featured speakers: Estevam Arantes (@Es7evam), Security Software Engineer, Microsoft Santiago Zanella-Béguelin (@xEFFFFFFF), Principal Researcher, Microsoft Mark your calendars: Security Chats: Inside the Research Process 🗓️ Part 1: August 26, 2025 | 10–11 AM PT 🗓️ Part 2: September 3, 2025 | 10–11 AM PT Register now: microsoft.eventsair.com/msrcsecchats/r… #ZeroDayQuest



