Skip to main content
MSRC

2025

Announcing the winners of the Adaptive Prompt Injection Challenge (LLMail-Inject)

Friday, March 14, 2025

We are excited to announce the winners of LLMail-Inject, our first Adaptive Prompt Injection Challenge! The challenge ran from December 2024 until February 2025 and was featured as one of the four official competitions of the 3rd IEEE Conference on Secure and Trustworthy Machine Learning (IEEE SaTML). The overall aims of this challenge were to advance the state-of-the-art defenses against indirect prompt injection attacks and to broaden awareness of these new techniques.

Jailbreaking is (mostly) simpler than you think

Thursday, March 13, 2025

Content warning: This blog post contains discussions of sensitive topics. These subjects may be distressing or triggering for some readers. Reader discretion is advised. Today, we are sharing insights on a simple, optimization-free jailbreak method called Context Compliance Attack (CCA), that has proven effective against most leading AI systems. We are disseminating this research to promote awareness and encourage system designers to implement appropriate safeguards.

Copilot (AI) 報奨金プログラムの画期的なアップデート : セキュリティを強化し、技術革新を促進します。 

Tuesday, February 11, 2025

本ブログは Exciting updates to the Copilot (AI) Bounty Program: Enhancing security and incentivizing innovation の抄訳版です。最新の情報は原文を参照してください。 マイクロソフト

Exciting updates to the Copilot (AI) Bounty Program: Enhancing security and incentivizing innovation

Friday, February 07, 2025

At Microsoft, we are committed to fostering a secure and innovative environment for our customers and users. As part of this commitment, we are thrilled to announce significant updates to our Copilot (AI) Bounty Program. These changes are designed to enhance the program’s effectiveness, incentivize broader participation, and ensure that our Copilot consumer products remain robust, safe, and secure.

Scaling Dynamic Application Security Testing (DAST)

Tuesday, January 21, 2025

Introduction Microsoft engineering teams use the Security Development Lifecycle to ensure our products are built in alignment with Microsoft’s Secure Future Initiative security principles: Secure by Design, Secure by Default, and Secure Operations. A key component of the Security Development Lifecycle is security testing, which aims to discover and mitigate security vulnerabilities before adversaries can exploit them.