

Live from Black Hat: Ransomware, Responsible Disclosure, and the Rise of AI
Aug 27, 2025
Tom Gallagher, VP of Engineering at Microsoft's Security Response Center, discusses the importance of responsible disclosure in cybersecurity and the exciting $5 million Zero Day Quest initiative. Eric Olson, Principal Security Researcher, dives into the explosive evolution of ransomware and social engineering tactics. He highlights the drastic reduction in ransomware dwell times to mere minutes and the emerging threat of AI-enhanced phishing attacks. Together, they emphasize the need for collaboration between researchers and security teams to combat these growing threats.
AI Snips
Chapters
Transcript
Episode notes
Coordinated Vulnerability Disclosure Protects Customers
- MSRC coordinates disclosure so researchers report vulnerabilities to Microsoft first and then jointly disclose after mitigations.
- This protects customers while letting researchers publicly share findings to advance community learning.
Diversity Drives Bug Research
- Microsoft's bug bounty community is globally diverse, spanning 59 countries and contributors from high schoolers to PhDs.
- That variety brings different perspectives and techniques that improve overall security discoveries.
Zero Day Quest: In-Person Research Sprint
- Zero Day Quest invited top researchers to Redmond for an in-person contest focused on cloud and AI vulnerabilities.
- Engineers and researchers worked side-by-side to triage, explain architectures, and accelerate fixes.