Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Recent content on Microsoft Security Response Center
Updated: 22 min 18 sec ago

Announcing the winners of the Adaptive Prompt Injection Challenge (LLMail-Inject)

Fri, 03/14/2025 - 07:00
We are excited to announce the winners of LLMail-Inject, our first Adaptive Prompt Injection Challenge! The challenge ran from December 2024 until February 2025 and was featured as one of the four official competitions of the 3rd IEEE Conference on Secure and Trustworthy Machine Learning (IEEE SaTML). The overall aims of this challenge were to advance the state-of-the-art defenses against indirect prompt injection attacks and to broaden awareness of these new techniques.
Categories: Microsoft

Jailbreaking is (mostly) simpler than you think

Thu, 03/13/2025 - 07:00
Content warning: This blog post contains discussions of sensitive topics. These subjects may be distressing or triggering for some readers. Reader discretion is advised. Today, we are sharing insights on a simple, optimization-free jailbreak method called Context Compliance Attack (CCA), that has proven effective against most leading AI systems. We are disseminating this research to promote awareness and encourage system designers to implement appropriate safeguards.
Categories: Microsoft

Exciting updates to the Copilot (AI) Bounty Program: Enhancing security and incentivizing innovation

Fri, 02/07/2025 - 08:00
At Microsoft, we are committed to fostering a secure and innovative environment for our customers and users. As part of this commitment, we are thrilled to announce significant updates to our Copilot (AI) Bounty Program. These changes are designed to enhance the program’s effectiveness, incentivize broader participation, and ensure that our Copilot consumer products remain robust, safe, and secure.
Categories: Microsoft

Scaling Dynamic Application Security Testing (DAST)

Tue, 01/21/2025 - 08:00
Table of Contents Introduction Why most enterprises have trouble scaling DAST Web endpoint discovery Automated OpenAPI Specification generation solutions that do scale (sort of) Authentication and authorization A scalable DAST solution Web endpoint discovery Authentication and authorization Authentication hook Authorization hook DAST orchestration platform architecture Conclusion and looking ahead Introduction Microsoft engineering teams use the Security Development Lifecycle to ensure our products are built in alignment with Microsoft’s Secure Future Initiative security principles: Secure by Design, Secure by Default, and Secure Operations.
Categories: Microsoft

Congratulations to the Top MSRC 2024 Q4 Security Researchers!

Wed, 01/15/2025 - 08:00
Congratulations to all the researchers recognized in this quarter’s Microsoft Researcher Recognition Program leaderboard! Thank you to everyone for your hard work and continued partnership to secure customers. The top three researchers of the 2024 Q4 Security Researcher Leaderboard are Suresh, VictorV, wkai! Check out the full list of researchers recognized this quarter here.
Categories: Microsoft