Microsoft Threat Intelligence @MsftSecIntel
We are Microsoft's global network of security experts. Follow for security research and threat intelligence. aka.ms/threatintelblog Redmond, WA Joined November 2010-
Tweets6K
-
Followers197K
-
Following994
-
Likes2K
Recorded live at Black Hat, Andrew “Spike” Grant of Huntress shares real-world observations from incident response, stories from years of interacting directly with threat actors, and insights into identifying suspicious activity before it escalates. msft.it/6018aZiGE Cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) and remote access tools to blend into normal activity, making it harder for defenders to distinguish authorized access from intrusion. Compromised access can be maintained through multiple remote access tools and later leveraged for ransomware deployment, data theft, or other follow-on activity, while AI-assisted phishing and social engineering continue to make initial compromise easier. Learn more on this episode of the Microsoft Threat Intelligence Podcast, hosted by Elliot Volkman.
Microsoft Security Research has observed an invoice fraud campaign that sent more than one million emails in three days, using templates that indicated AI-assisted development, including verbose HTML comments, structured labels, uniform construction. msft.it/6016akhVn The campaign used executive impersonation, fake vendor invoices, lookalike domains, and third-party email delivery infrastructure to target finance personnel. It combined spoofed sender and reply-to display names, executive signatures, fabricated forwarded conversations, and ACH requests of nearly $50,000. Read our latest blog for IOCs, Microsoft Defender detections, mitigation guidance, and recommendations for email authentication, spoof protection, and other configurations.
Microsoft developed the Cloud web applications threat matrix to organize relevant techniques across cloud-hosted web applications and serverless platforms using MITRE ATT&CK tactics. msft.it/6015ak507 The matrix can help security teams assess visibility gaps, prioritize hardening, and plan investigations across application code, managed runtimes, workload identities, deployment pipelines, and connected cloud resources. Read the blog to learn more about the framework, the technique catalog, and guidance for reducing exposure across cloud-native environments.
Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins are followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, and cloud data access. msft.it/6010aknRC The activity begins with identity-focused social engineering, progresses through authentication persistence and cloud reconnaissance, and is followed by targeted data access consistent with data collection and potential exfiltration. Microsoft Threat Intelligence assesses that the initial access activity observed in this campaign is used by multiple threat actors, including Storm-3121, Storm-3032, and others. Defenders should focus on the behavioral sequence rather than individual indicators. Monitor for unusual sign-ins, authentication method changes, Microsoft Graph reconnaissance, and abnormal cloud data access. Read the research for detections and hunting guidance.
The September 2026 security updates are available. In addition, starting today, Microsoft is publishing Vulnerability Exploitability eXchange (VEX) statements for all Microsoft-assigned CVEs. Learn more: msft.it/6012aXv5M
Security updates for September are now available: msft.it/6018SZEg0. Alongside this month's release, we're expanding machine-readable Vulnerability Exploitability eXchange (VEX) coverage to all Microsoft-assigned CVEs, providing customers with more consistent,
Microsoft Security Researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt injection research as ASCII smuggling, to obscure financial lure words before email filters parsed them. msft.it/6017apIGx Microsoft telemetry linked the technique to a large-scale finance-themed phishing operation that persisted for months, using hundreds of rotating sender domains and consistent infrastructure patterns. The research shows how techniques popularized in AI security research can quickly cross into traditional phishing campaigns as threat actors adapt tradecraft across domains. Learn how to identify this activity and strengthen detection against similar tradecraft.
Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel & abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution & C2. msft.it/6010apXAw After establishing access, the attackers use trusted tooling to perform reconnaissance, capture screenshots, execute follow-on payloads, and move laterally toward domain controllers, certificate authorities, and other high-value systems. Organizations should restrict Teams external access to trusted domains, reinforce user education, and harden systems against social engineering. Read the blog for analysis, Microsoft Defender coverage, indicators, hunting queries, and mitigation guidance.
Microsoft Defender Experts is tracking a malware campaign that uses counterfeit software-download sites impersonating trusted vendors and dynamically generated installer archives to deliver multistage payloads leading to system compromise. msft.it/6011aTt3H Once executed, the malware payloads establish persistence through scheduled tasks, abuse trusted binaries, leverage a legitimate updater framework for payload delivery, inject code into legitimate processes, and communicate with command-and-control infrastructure over non-standard ports. Defenders should prioritize preventing downloads from untrusted sources and hunting for behavioral indicators rather than file names or hashes, which can rotate. Read the blog for an in-depth technical analysis, along with detection, mitigation, and hunting information.
Microsoft Security Research has published an in-depth technical analysis of this TerminalFix campaign, including the attack chain, indicators of compromise, as well as detections, mitigations, and hunting guidance: msft.it/6018aRXJG
Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host. This TerminalFix campaign uses fake CAPTCHA verification prompts to facilitate user-executed PowerShell commands. Beyond the initial lure, this campaign uses DLL sideloading through LockScreenContentServer.exe, steganographic payload delivery, and persistence mechanisms. It then performs extensive reconnaissance to identify reachable systems and key infrastructure. Organizations should investigate devices where users interacted with suspicious CAPTCHA verification prompts and look for unusual execution of LockScreenContentServer.exe, hidden ProgramData folders, and outbound connections associated with the activity. Additional guidance and technical analysis will be published soon by Microsoft Security Research.
Microsoft is observing threat actors increasingly target AI infrastructure concentrating credentials, data access, model connectivity, and execution privileges, creating new opportunities to gain access, establish persistence, and monetize environments. msft.it/6017aPhKH Across multiple AI workload intrusions, attackers used different access paths but consistently sought provider credentials, database access, workflow execution, container visibility, and other resources that could support follow-on activity beyond the initially compromised system. AI infrastructure is increasingly functioning as a control plane where credential theft, host compromise, and downstream data access can converge, making these platforms attractive targets for threat actors. Read the Microsoft Security Research blog for additional analysis and guidance.
The ransomware attack dubbed “JADEPUFFER”, one of the first documented cases of a threat actor using large language model (LLM) to conduct an end-to-end attack, offers a glimpse into how AI could shape future ransomware campaigns. msft.it/6013aPFdv While the attack relied on familiar techniques, it demonstrated how AI can rapidly iterate, adapt to failures, and continue progressing toward an objective. In this episode of the Microsoft Threat Intelligence Podcast, Elliot Volkman speaks with Michael Clark and Crystal Morin of Sysdig about the AI-driven activity, including its ability to generate and modify code, reason through errors, and work through technical obstacles that might slow a human operator. Despite its use of AI, JADEPUFFER relied on familiar weaknesses, including exposed services, unpatched vulnerabilities, and poor credential hygiene, highlighting the continued importance of exposure management and foundational security practices.
Microsoft Defender is monitoring the active exploitation of the CVE-2026-65400 improper authentication vulnerability on a limited number of macOS devices, with telemetry showing successful root account network sign-ins through Screen Sharing. Microsoft urges customers to immediately apply security updates and to investigate related Microsoft Defender alerts and detections. After gaining access, the attackers transferred files (scripts and a Secure Shell (SSH) public key) to the devices through Screen Sharing, established SSH persistence, removed histories and logs, modified Packet Filter settings, and deployed the cryptocurrency miner XMRig 6.26.0. They copied and ad-hoc signed XMRig as a hidden .config/sysmond binary, masqueraded it as com[.]apple[.]airportd, and persisted it with a KeepAlive LaunchDaemon. Indicators of compromise (IOCs): - SHA-256: 84006055916e267f7c2f9324f1848563e589e4526a296d4e9e9ce8e2112d357c (customized XMRig binary produced on multiple affected devices after the stock miner binary was copied, renamed to sysmond, and ad-hoc signed) - /private/var/root/.config/sysmond (hidden path used for the customized miner) - /Library/LaunchDaemons/com.xmr.miner.plist (malicious RunAtLoad and KeepAlive persistence) - exec -a com[.]apple[.]airportd (command-line masquerading used to present the miner as an Apple process) - 4AUZ9XNsffcPn13Yjk5yWAaZg8x5Fgu9cL9kWwDCnmACUFLuwrLg41WU31qiKfmo9ee62mVbwG9F5G82Ko8vck8nCtxdicj (Monero wallet reused across the observed deployments) - auto[.]c3pool[.]org:443 (mining-pool endpoint used by the miner; treat as contextual because mining pools may also receive legitimate traffic) The stock XMRig binary and its legitimate GitHub release URL should not be treated as malicious without the surrounding adversary technique context. Microsoft Defender alerts and detections: - 'CoinMiner' malware was prevented (Investigate retained SSH access, hidden miner copies, and com.xmr.miner.plist, even when quarantine succeeds) - Suspicious file or content ingress (Inspect the responsible process, destination, signing state, and nearby persistence) - Suspicious connection to remote service (Investigate unexpected root SSH sessions and sshd-session -i -R) When hunting, higher-confidence signals combine root-level Screen Sharing file transfer activity through SSFileCopyReceiver with writes to privileged .ssh, /private/etc, hidden /private/var/tmp, or LaunchDaemon paths. Microsoft recommends updating macOS to at least Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9; disabling unnecessary Screen Sharing; blocking untrusted TCP/5900 access; inspecting SSH keys and LaunchDaemons; removing unauthorized persistence; and rotating affected credentials.
Microsoft Defender Experts’ analysis of MacSync Stealer, a macOS-focused infostealer that relies on constantly changing infrastructure for payload delivery, C2, and exfiltration, demonstrates that malicious domains rotate quickly, but attacker behavior often remains consistent. msft.it/6012azMLa By correlating recurring endpoint and network behaviors, including execution patterns, request characteristics, staging behavior, and upload methods, Microsoft Defender Experts uncovered related domains and identified durable detection and hunting pivots. Read our latest blog to learn how to hunt for MacSync Stealer beyond static indicators of compromise (IOCs), and get detection, mitigation, and hunting guidance to help investigate and respond to this threat.
In this episode of the Microsoft Threat Intelligence Podcast, Principal Threat Intelligence Analyst Crane Hassold explores how phishing and social engineering attacks are evolving beyond email in the threat landscape. msft.it/6013aydVt While email remains the primary attack vector, Microsoft is tracking a broader social engineering landscape that includes QR code phishing, CAPTCHA-gated phishing, Teams-based impersonation, and credential theft campaigns designed to reach users across business communication channels. msft.it/6014aydVQ As organizations adopt new ways of communicating, threat actors continue to adapt alongside them, targeting users through the platforms they trust and use every day. Hear more about practical defensive measures and how to reduce exposure to evolving threats in this episode. As the Microsoft Threat Intelligence Podcast enters a new season, we want to thank Sherrod DeGrippo for 3.5 years of expert insight, thoughtful conversations, and leadership as host. Listen to her farewell episode: msft.it/6015aydVv
Based on leak site data tracked by Microsoft Threat Intelligence, The Gentlemen ransomware has claimed one of the highest victim counts among ransomware-as-a-service (RaaS) operations over the past three months, while Microsoft Defender detections on active ransomware offerings show it is the fourth most impactful payload after Akira, Qilin, and LockBit. msft.it/6017aHAXl Microsoft tracks the operators of The Gentlemen ransomware as Storm-2697, a financially motivated threat actor that manages the RaaS platform while affiliates carry out attacks. The ransomware combines strong per-file encryption with self-propagation capabilities, which could enable affiliates to expand access across compromised environments and increase the scale of an intrusion. Organizations can reduce risk by hardening identities, limiting privileged access, and leveraging EDR capabilities to identify ransomware activity early.
The August 2026 security updates are available:
Security updates for August 2026 are now available. Details are here: msft.it/6018SZEg0
Florian Roth ⚡️ @cyb3rops
224K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
BleepingComputer @BleepinComputer
258K Followers 206 Following Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
mRr3b00t @UK_Daniel_Card
126K Followers 8K Following Chief Artificial Intelligence Cyber Security Scientist Counter Brain Worms Collective Member former Helpdesk AI infection status: clean
Justin Elze @HackingLZ
74K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
DebugPrivilege @DebugPrivilege
41K Followers 2K Following Not active anymore on X. Network Defender. Problem solver with a passion for troubleshooting complex issues.
Stephan Berger @malmoeb
30K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Grzegorz Tworek @0gtweet
39K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Matt Zorich @reprise_99
16K Followers 2K Following @Microsoft Security | https://t.co/HWozKuixTi | Tweets are my own | 🇦🇺
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Will @BushidoToken
39K Followers 3K Following Senior Threat Intel Advisor @TeamCymru Co-founder @CuratedIntel Co-author @SANSForensics FOR589 Co-founder @BSidesBournemth #126: REvil @darknetdiaries
Chris Sanders 🔎 �... @chrissanders88
36K Followers 488 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
DirectoryRanger @DirectoryRanger
37K Followers 108 Following This account assembles and disseminates information related to Active Directory and Windows security.
blackorbird @blackorbird
44K Followers 703 Following Peace and Love. Just Analysis/Hunter/Youtuber/AiCoder/Entrepreneur/. #APT #threatIntelligence #Exploit #CTI #meme #cyber #hacker #OSINT #Ai Need Remote Job
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Will Dormann is on Ma... @wdormann
27K Followers 1K Following I play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here: @[email protected] https://t.co/hXggdAVkSQ
Speaker 25 @rodtrent
18K Followers 2K Following Christian. Husband. Father. Runner. Speaker. Author. Capitalist. Cyber and AI at Microsoft. Dude/Bro.
Michael Koczwara @MichalKoczwara
25K Followers 2K Following Threat Researcher/Founder @Intel_Ops_io Threat Intelligence, Adversary Infrastructure Hunting, Curated TI Feed (Coming Soon) https://t.co/VQWaze6gaF
rootsecdev @rootsecdev
27K Followers 1K Following Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
Kostas @Kostastsale
21K Followers 498 Following I like building things that solve real problems, working across cybersecurity, product, and research | 🇬🇷🇨🇦
Thomas Roccia 🤘 @fr0gger_
35K Followers 2K Following Founder @SecurityBreakAI AI Security x Threat Intel · Threat Researcher · Creator of #Unprotect & #NOVA · Python 🧡 · Prev @Microsoft @McAfee_Labs
Vaja Lomtatidze @VLomtatidze
2 Followers 100 Following
Fury @FuriousSt0rm
1 Followers 16 Following
SecOps @neosharesecops
0 Followers 8 Following
John Smith @JohnSmithxz0r
3 Followers 28 Following
FlyingCircus @FlyingCircusCGN
0 Followers 6 Following
Ann @TheRealAnn38
3 Followers 208 Following
mreboiro @mreboiro37
14 Followers 406 Following
Hoàng Việt Anh @m0skv42004
0 Followers 4 Following
Ricky @Rickyyqe
1 Followers 17 Following
BlackHex @blackhex000
1 Followers 25 Following Starting my Cybersecurity journey 🛡️ | Arch Linux, Python & Packet Analysis | Learning on TryHackMe | #CyberSecurity #InfoSec
阳光宅男 @StNL8PSuGm2lzr9
8 Followers 235 Following
Erwin @TabascoPaw
1 Followers 17 Following
كريم ممدوح �... @agt2029
0 Followers 89 Following
Kris Hatlelid @khatlelid
177 Followers 724 Following leader of security teams; maker and player of video games and software. on a good evening I might play piano bar. my opinions are mine only.
Eric Kelleher @ekoktacoo
5 Followers 114 Following
M Q Ansari @m_q_ansari
9 Followers 400 Following
Elliptyc @elliptyc
2 Followers 1K Following
K9rJ @sarthi88
39 Followers 893 Following
Robert Munzy @MunzyRobert
37 Followers 249 Following Cybersecurity - Current U.S Army Combat Veteran - 82nd Airborne Division, 173rd Airborne Brigade
۟ @inataqlAduaS
24 Followers 116 Following
1.bin @Hourrorizon
0 Followers 25 Following
1rfninja @1RFNinja
62 Followers 3K Following
iscar47 🦅🇺🇸�... @iscar47
69 Followers 3K Following
Sharif AAF @0x16a4f
3 Followers 110 Following
Imran Ahmed @imranahmed005
119 Followers 93 Following DevOps + Cyber Security | I build SOC detections and break them on purpose | Writing about real incidents, not theory | CVE breakdowns and hands-on defence
𝐀𝐫𝐝𝐞𝐧 ... @Arden_toolz
1K Followers 157 Following 𝐄𝐬𝐬𝐞𝐧𝐭𝐢𝐚𝐥 𝐀𝐜𝐜𝐨𝐮𝐧𝐭 𝐃𝐚𝐭𝐚 𝐑𝐞𝐜𝐨𝐯𝐞𝐫𝐲 𝐒𝐞𝐫𝐯𝐢𝐜𝐞𝐬 DM me on Telegram for swift replies
"Artificial Intellige... @GermanHillhouse
2 Followers 655 Following @BulthuisWest's earthly father. I'm a #supertramp. #50states 60+jobs 30+homes 20+towns #bicycle #freights #hitch #trafficked #20years @FreemensParty #capitalism
BhrandonBorges @BhrandonBorges
148 Followers 403 Following
Brad Jones @SnoBrad
2 Followers 75 Following
esmadi abdul hamid @esmadi
26 Followers 94 Following
Abmilion @abmilion11486
4 Followers 27 Following
سِرداب | قصص... @Sirdaab
0 Followers 15 Following قصص موثّقة عن الاختراق والتجسّس والجرائم السيبرانية. نتتبّع ما حدث، كيف انكشف، وما بقي مجهولًا. بالعربية، مع المصادر.
Mondo Windows @MondoWindows
133 Followers 64 Following Account ufficiale del sito dedicato ai sistemi operativi Microsoft Windows. Storia, applicazioni, giochi e novità sul Mondo Windows!
CyberFight @CyberFightApp
0 Followers 14 Following Daily nation-state cyber threat assessments for US organizations. Every fact cited. Every judgment confidence-rated. IC-grade tradecraft. Open sources only.
Felix @FelixRBSEC
0 Followers 35 Following
Tony D Truong Troicao... @troicaolenh00
200 Followers 3K Following Troicaolenh 07051976 gay male single by legal status, is troi last name , Troi Last name as brand new as USA citizens
Dominic Scott @Dominic64426965
0 Followers 8 Following
Devence lab @devencelabs
0 Followers 19 Following Applied research lab for safe and autonomous AI systems Making agentic AI safe to operate at enterprise scale
Issika Aymeric Kouam�... @issikaaymeric
8 Followers 240 Following 21 | cs student | startup | creativity | AI https://t.co/k3ZfnsucIx https://t.co/19g9eegK28
Florian Roth ⚡️ @cyb3rops
224K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
MalwareHunterTeam @malwrhunterteam
257K Followers 39 Following Official MHT Twitter account. Check out ID Ransomware (created by @demonslay335). More photos & gifs, less malware.
BleepingComputer @BleepinComputer
258K Followers 206 Following Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
mRr3b00t @UK_Daniel_Card
126K Followers 8K Following Chief Artificial Intelligence Cyber Security Scientist Counter Brain Worms Collective Member former Helpdesk AI infection status: clean
DebugPrivilege @DebugPrivilege
41K Followers 2K Following Not active anymore on X. Network Defender. Problem solver with a passion for troubleshooting complex issues.
Unit 42 @Unit42_Intel
71K Followers 81 Following The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
Matt Zorich @reprise_99
16K Followers 2K Following @Microsoft Security | https://t.co/HWozKuixTi | Tweets are my own | 🇦🇺
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
rootsecdev @rootsecdev
27K Followers 1K Following Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
Thomas Roccia 🤘 @fr0gger_
35K Followers 2K Following Founder @SecurityBreakAI AI Security x Threat Intel · Threat Researcher · Creator of #Unprotect & #NOVA · Python 🧡 · Prev @Microsoft @McAfee_Labs
Catalin Cimpanu @campuscodi
106K Followers 2K Following Cybersecurity reporter. I'm mostly active on BlueSky and Mastodon.
hasherezade @hasherezade
91K Followers 968 Following Programmer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
Virus Bulletin @virusbtn
62K Followers 1K Following Security information portal, testing and certification body. Organisers of the annual Virus Bulletin conference. @[email protected]
x0rz @x0rz
95K Followers 420 Following Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓
Dark Reading @DarkReading
357K Followers 49 Following One of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
Microsoft Mechanics @MSFTMechanics
149K Followers 379 Following Why, How & When to use current and forthcoming Microsoft Tech. Hosted by Microsoft Director @DeployJeremy & colleagues. An official @Microsoft video series.
Karsten Hahn @struppigel
26K Followers 783 Following MalwareAnalysisForHedgehogs, Principal Malware Researcher at GDATA, he/him 🦔🌈🏳️⚧️
Microsoft Security @msftsecurity
344K Followers 320 Following Be first to know about AI, threats, and new tools. Quick hits, expert tips, and real-time security news—follow for smarter, safer ops.
CISA Cyber @CISACyber
302K Followers 71 Following Part of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
Jason Geffner @JasonGeffner
2K Followers 265 Following I’ve moved to Bluesky — https://t.co/Lpz3RZMp3U
waymon @obnoxious4n6
655 Followers 1K Following Sr. Security Research Manager @Microsoft GHOST || 👻 Threat Hunting 👻 || tryin to navigate this cyber stuff || tweets == my own
Joe Hannon @JoeHannon52
526 Followers 1K Following Security researcher @ MSTIC, Microsoft https://t.co/8IO8nzNnAQ
Wojska Obrony Cyberpr... @CyberWojska
24K Followers 30 Following Witamy na oficjalnym profilu Wojsk Obrony Cyberprzestrzeni. Cyber Command. #CyberAktywni #CyberBezpieczni #CyberSkuteczni
Matthew Kennedy @_matt_kennedy
364 Followers 217 Following Manager at Microsoft Threat Intelligence Center. Adjunct Faculty at Georgetown University. Penn State Alum. Tweets are my own.
Scott Hanselman 🌮 @shanselman
335K Followers 10K Following VP, Member of Technical Staff @ MSFT/GitHub - Code, OSS, STEM, Beyoncé, T1D, #DevRel YouTube/TikTok and listen to the @Hanselminutes tech podcast
Michael Howard @michael_howard
4K Followers 155 Following Software security @MSFT working on Azure. Co-author of 'Designing and Developing Secure Azure Solutions' and Co-host of the Azure Security Podcast.
Eric Geller @ericgeller
76K Followers 821 Following Senior reporter at @CyberSecDive covering all things digital security. I also co-host @hothtakes. | Send me tips: https://t.co/XevCjdQhqz
CYBERWARCON @CYBERWARCON
6K Followers 568 Following #CYBERWARCON 2025 Registration and CFP are now open | 📧 Subscribe to receive updates at https://t.co/5lb0WvK6MJ
OpenAI @OpenAI
5.4M Followers 4 Following OpenAI’s mission is to ensure that artificial general intelligence benefits all of humanity. We’re hiring: https://t.co/dJGr6LgzPA
Jesse D'Aguanno @0x30n
2K Followers 622 Following Hacker, Vuln Research, 2x winner DEF CON CTF, Founder & CEO Blackwing Intelligence (@blackwinghq), not a CISSP (@[email protected])
Sarah Young @_sarahyo
10K Followers 1K Following Ex - Security & AI stuff @microsoft | Co-host of @AzureSecPod | Mother of shibes | Mostly dogs, carbs & security posts | Opinions mine
christine 🌸💐�... @x71n3
1K Followers 895 Following 'Don't miss opportunities because you think that ideas aren't important unless they're complicated. Simple ideas are often the most powerful.' -Patrick Winston
Lauren Leigh @LaurenLeigh522
270 Followers 537 Following Intelligence Analyst. (Former) dancer. Not good at tweeting but love reading and liking tweets from others! Views are mine not my employer’s.
Sarah Armstrong-Smith @SarahASmith75
5K Followers 2K Following Exec Security & Crisis Leader, Global Keynote Speaker, Best Selling Author, Lover of Doggos. Eternal Optimist! Aston Baby. All views my own 🇬🇧
John Scott-Railton @jsrailton
166K Followers 3K Following Chasing digital badness. Sr. Researcher @citizenlab @UofT @munkschool. Founding.Fmr.Ed. @SecPlanner. Tweets mine. Other platforms @jsrailton too.
The Citizen Lab @citizenlab
119K Followers 1K Following Academic research unit at @UofT investigating novel threats to democracy, human rights, and global security in the digital ecosystem.
Pawel Partyka @Pawp81
1K Followers 328 Following Amateur cyclist and swimmer. Security Researcher in Microsoft. Tweets are mine.
💻 Sherrod @sherrod_im
39K Followers 7K Following Difficult mystery girl connected to the divine forces of the universe.
MITRE @MITREcorp
20K Followers 2K Following Applying systems thinking to national challenges in AI, cybersecurity, healthcare, transportation, and national security.
Chris Eng @chriseng
12K Followers 847 Following Cybersecurity Exec | Traveler | Food Enthusiast | Dad | Public Speaker | IG:chrisplusfilters | https://t.co/g6xuBsrCaX
D̒̕ᵈăᵃn̕ᶰ ... @Viss
43K Followers 727 Following @[email protected] Founder/CTO, Phobos Group :: spiceshop = https://t.co/h9ioG1Ykn7 :: quad flooper : scoville addict ::public speaker :: food pornographer
Sick.Codes @sickcodes
17K Followers 6K Following Security researcher 🇦🇺 Good-faith hacking 🤡 Weaponizing source code 🧬 https://t.co/qulkQaGWp9
Callum @callum_infosec
282 Followers 109 Following
Sil @kyotorocks
105 Followers 536 Following Threat Intelligence Manager / Reverse Engineer @ Microsoft Threat Intelligence Center (MSTIC). Tweets are my own.
Michael Peck @mpeck2
59 Followers 617 Following Android/iOS/Linux/macOS endpoint threat protection research lead, opinions are my own
Dimitri Os @Ch0pin
5K Followers 30 Following Senior Security Researcher @Microsoft | Android Security Obsessed | Pwn2Own 2025 | Side projects → https://t.co/olbzNZlyrY
thomasg @thomas_0x47
153 Followers 298 Following Threat Analyst @ Microsoft Threat Intelligence Center #MSTIC. Tweets and opinions my own
Tal Maor @talthemaor
1K Followers 425 Following Security Researcher @Microsoft #MicrosoftThreatIntelligence Tweets are my own personal opinion.
Philip Tsukerman @PhilipTsukerman
3K Followers 81 Following I sometimes tweet about security stuff. Pondering whether to turn this into a music-focused account instead...
Sixdub @sixdub
11K Followers 1K Following Microsoft Threat Intelligence | Student @ GMU Antonin Scalia Law School | USAFA '10 & USAF Veteran | Focus: Intelligence, Technology, Cyber Law, Leadership
Not on here anymore, ... @malwaretech
30K Followers 2 Following No longer using Twitter. Check out https://t.co/BYnF2Aml7H for where to find me.
msticpy @msticpy
835 Followers 20 Following #msticpy is an open source library for InfoSec investigation and hunting in #Jupyter Notebooks and #Python.
Jenna McLaughlin @JennaMC_Laugh
35K Followers 4K Following @NPR cybersecurity correspondent. I don't regularly use this account.
jeff stone @jeffstone500
6K Followers 934 Following **Not on Twitter anymore** editor @business tracking info ops, scams, hacks + weirdness. Bluesky: https://t.co/DiziPIypyI Signal: 1-716-249-1677
Amy Hogan-Burney @CyberAmyHB
878 Followers 153 Following Brockton Royalty. Cybersecurity @Microsoft - working to secure the digital ecosystem. Still wearing great shoes. Tweets are all mine.
Ajeet @PrakashAjeet
1K Followers 409 Following Security Person at Microsoft. Microsoft Threat Intelligence Center, #AzureSentinel. #AzureSecurityCenter. Opinions are my own.
bk (Ben Koehl) @bkMSFT
3K Followers 798 Following Threat Intelligence at @Microsoft Threat Intelligence Center (MSTIC).
Dan Taylor @DeltaTangoTwo
852 Followers 2K Following
Alex Weinert @Alex_T_Weinert
5K Followers 703 Following VP Director of Identity Security at Microsoft. he/him.
Mark Parsons @markpars0ns
2K Followers 819 Following Threat Analyst @ Microsoft - mostly tweet about astrophotography and occasional some work. Tweets are my own















