🎤 BlueHat Redmond speaker announcement
We're excited to announce Varsha Chahal and Henrique Pereira (@ikkebr), Senior Security Engineers at Microsoft, will be speaking at BlueHat Redmond with their talk, “Gotta Catch’em All: Hunting Azure Anonymous Functions in the Wild.”
Azure Functions often expose anonymous HTTP endpoints, creating a broad and overlooked attack surface. In this session, Varsha and Henrique share how they identified and exploited vulnerabilities at scale, leading to 40+ MSRC cases, including multiple high-impact issues.
From CodeQL to automated exploitation pipelines, learn how small misconfigurations can turn into critical cloud risks and how defenders can better secure serverless workloads.
#BlueHat
📣The BlueHat Asia Call for Papers is now open! 📣
BlueHat brings together security researchers and defenders to exchange ideas, experiences, and best practices. We’re looking for talks on novel research that hasn’t been presented before, including vulnerability research, mitigations, emerging threats and techniques, and related areas across the security landscape.
📍Singapore | September 17–18, 2026
🗓️CFP deadline: June 15, 2026
Submit your paper now: https://t.co/BAtZHRg7co
There is a lot of momentum around AI in cybersecurity and its ability to improve security outcomes at scale. At Microsoft, we are applying these capabilities to our long-standing work with the community to find and mitigate vulnerabilities more quickly and augmenting our security and development toolsets so we can better protect customers and Microsoft.
Read more: https://t.co/0GqRtiJMSn
I don’t have the word to fully articulate how great this event is. The benefits are layered and invaluable. It’s fun. It’s collaborative but most of all, it’s protecting you, the customers! Thank you researchers for what you do and thank you @msftsecresponse for this event.
Day 1 of the Zero Day Quest Onsite Hacking Event is in the books and we’ve kicked off Day 2.
We welcomed top security researchers from around the world to Microsoft’s Redmond campus for a day of live hacking, collaboration, and connection.
Researchers worked side-by-side with Microsoft engineers and product teams to identify vulnerabilities across our AI and cloud platforms. Lots of amazing reports and discussions flowed throughout the day with MSRC, product teams, and the researchers themselves all driving security forward together.
We wrapped the day with a Seattle Kraken vs. Tampa Bay Lightning game in Seattle (tough loss, but the vibes were strong!).
We’re incredibly grateful to the security researcher community. Your work makes a real impact in helping protect customers.
#ZeroDayQuest
Today, we’re welcoming top security researchers from around the world to Microsoft’s Redmond campus for the first official day of the Zero Day Quest Onsite Hacking Event. They’ll collaborate with Microsoft engineers and product teams to uncover vulnerabilities across our AI and cloud platforms over the next two days.
We’re thankful for the security researcher community and the impact their work has in helping protect customers.
#ZeroDayQuest
We’re excited to welcome some of the world’s top security researchers to Zero Day Quest 2026 🎉
We kicked off the onsite hacking event with bowling, followed by dinner and drinks with incredible views. It’s the start of a full week of security research, collaboration with Microsoft teams, and social events including a Kraken hockey game, a brunch cruise, and more.
We’re grateful to every researcher who qualified and joined us in person, as well as those participating remotely. Their work and partnership with Microsoft help protect customers and communities around the world.
#ZeroDayQuest
The global security research community plays a critical role in protecting Microsoft customers. As Tom Gallagher (@secbughunter), VP of Engineering at MSRC, shares in today’s announcement, we’re evolving how researcher impact is recognized.
Starting with the July 2026 Most Valuable Researcher (MVR) leaderboard, rankings will be based on bounty award amounts, providing a consistent signal that aligns recognition with vulnerability severity and security outcomes. We’re also introducing honorable mentions to recognize all researchers who submit valid vulnerability reports, independent of ranking.
Read the full announcement for more details: https://t.co/PY2amshwcm
In our latest blog, Cameron Vincent (@SecretlyHidden1), Senior Security Researcher at MSRC, features the work of MSRC intern and security researcher, Brian McNulty (@brianjmcnulty), who uncovered 22+ critical vulnerabilities in just two months. Learn how the MSRC team leverages automation and tools like IMPOSTR to identify risky multi-tenant apps, why robust authentication and authorization are essential, and how new protocols like Model Context Protocol (MCP) are shaping the future of secure AI integration.
This blog covers:
• Real-world attack scenarios and variant hunting strategies
• Securing multi-tenant authentication and authorization flows
• Lessons learned from MCP vulnerabilities and Azure template exposures
If you’re a security researcher, CISO, or technical leader interested in advanced detection techniques and evolving best practices, see how MSRC is raising the bar for proactive defense.
Read the full blog post here: https://t.co/41kaFXnVnV
At BlueHat Asia, we have 6 unique security villages to explore, each packed with hands-on opportunities and practical learnings. Check out the attached video to learn more:
➤ Phishing Village: Sharpen your detection and response skills with live CTFs, quizzes, and AI-driven simulations.
➤ MSRC Village: Engage with researchers, enter the raffle contest, and tackle CTF challenges of varying difficulty.
➤ AI Security Village: Dive into the intersection of cybersecurity and AI. Defend against and simulate AI-powered attacks while competing for leaderboard glory.
➤ AppSec Village: Strengthen your application security expertise with hands-on modules for every skill level, from pentesters to blue teamers.
➤ Forensics & Attack Village: Explore digital forensics across platforms with quizzes, CTFs, and interactive demos. Experience an innovative CTF where you trace adversaries, map exploit chains, and learn practical graph analysis techniques.
➤ IoT Village: Step into the world of IoT and drone security, where physical and digital threats converge. Solve CTFs that test your skills in real-world scenarios.
#BlueHatAsia
We’re excited to announce our next BlueHat Asia speaker, Tzah Pahima (@TzahPahima), an independent Cloud Security Researcher renowned for uncovering and exploiting vulnerabilities in the cloud ecosystem. Tzah’s expertise spans vulnerability research and web security, making him a leading voice in advancing secure cloud practices.
With a background that includes five years of service in an Israeli military intelligence unit, Tzah brings a unique perspective and deep technical insight to the field. Expect an engaging session packed with real-world examples, cutting-edge techniques, and actionable strategies for strengthening cloud security.
#BlueHatAsia
We’re excited to announce our next BlueHat Asia speakers: Brian McNulty (@brianjmcnulty) and Cameron Vincent (@SecretlyHidden1)! Cameron is a Senior Security Researcher at Microsoft, specializing in vulnerabilities and mitigation within MSRC. From reproducing bug reports to variant hunting, Cameron has spent the last decade identifying and mitigating trends to protect the Microsoft ecosystem. His research focuses on authentication and authorization vulnerabilities, an area he’s been passionate about for over 10 years.
Brian began making a name for himself through Meta’s bug bounty program and is just getting started. Currently a student at the University of Michigan, Brian has proven his skills as a 2025 MSRC intern and as a top player in the bug bounty world, ranking in Meta’s top 5 multiple times. He’s also working toward his master’s in computer science, continuing to push boundaries in security research.
Their upcoming talk will take you inside the MSRC Vulnerabilities & Mitigations team, exploring how variant hunting and deep issue analysis help secure the Microsoft ecosystem.
#BlueHatAsia
Thank you, @_dirkjan, for partnering with the MSRC to protect customers. Your work demonstrates the power of coordinated vulnerability disclosure and community collaboration.