{"id":58293,"date":"2025-03-13T16:00:00","date_gmt":"2025-03-13T16:00:00","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/"},"modified":"2025-03-13T16:00:00","modified_gmt":"2025-03-13T16:00:00","slug":"how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/","title":{"rendered":"How MSRC coordinates vulnerability research and disclosure while building community"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Security_1028749_Blog_250307.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>In an era where discovering and rapidly mitigating security vulnerabilities is more important than ever before, the <a href=\"https:\/\/msrc.microsoft.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Security Response Center (MSRC)<\/a> is at the center of this work. MSRC focuses on investigating vulnerabilities, coordinating their disclosure, and releasing security updates to help protect customers and Microsoft from current and emerging cyberthreats related to security and privacy. MSRC partners with product teams across Microsoft\u2014as well as external security researchers\u2014to investigate reports of security vulnerabilities affecting Microsoft products and services.<\/p>\n<p>MSRC also fosters the development of a stronger and more effective security researcher community through a variety of initiatives, including the <a href=\"https:\/\/microsoft.com\/msrc\/bounty\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft bug bounty program<\/a>, the <a href=\"https:\/\/www.microsoft.com\/bluehat\/\" target=\"_blank\" rel=\"noreferrer noopener\">BlueHat security conference<\/a>, the <a href=\"https:\/\/msrc.microsoft.com\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">MSRC blog<\/a>, and internal security training for engineers.<\/p>\n<p>Microsoft uses a Coordinated Vulnerability Disclosure (CVD) process that recognizes security researchers while disclosing vulnerabilities in a responsible and timely manner. <\/p>\n<h2 class=\"wp-block-heading\" id=\"collaboration-through-bug-bounty-programs-and-researcher-recognition\">Collaboration through bug bounty programs and researcher recognition<\/h2>\n<p>Security researchers are incentivized to find vulnerabilities and report them through a Coordinated Vulnerability Disclosure (CVD) process. Some reported vulnerabilities are eligible for rewards as part of Microsoft\u2019s bug bounty programs. These programs are an important part of our proactive strategy of incentivizing the external security research community to partner with us and help protect our customers from security threats. Since its inception in 2013, Microsoft\u2019s bug bounty programs have <a href=\"https:\/\/msrc.microsoft.com\/blog\/2023\/11\/celebrating-ten-years-of-the-microsoft-bug-bounty-program-and-more-than-60m-awarded\/\" target=\"_blank\" rel=\"noreferrer noopener\">awarded more than $60 million<\/a> in bounties to security researchers.<\/p>\n<p>In 2024, we announced expansions to several existing bounty programs, and launched a new <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/bounty-defender\" target=\"_blank\" rel=\"noreferrer noopener\">Defender Bounty Program<\/a> and <a href=\"https:\/\/aka.ms\/aibounty\" target=\"_blank\" rel=\"noreferrer noopener\">AI Bounty Program<\/a>. We also expanded our bug bounty programs with <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/11\/securing-ai-and-cloud-with-the-zero-day-quest\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Zero Day Quest<\/a>, which adds $4 million in potential bug bounty rewards for research into high-impact areas, specifically cloud and AI. Security researchers who report a vulnerability that isn\u2019t eligible for a bug bounty can still take part in the <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/researcher-recognition-program\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Researcher Recognition Program<\/a>&nbsp;and be recognized for their work on the&nbsp;<a href=\"https:\/\/msrc.microsoft.com\/leaderboard\">Researcher Leaderboard<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"coordinated-vulnerability-disclosure-cvd\">Coordinated Vulnerability Disclosure (CVD)<\/h2>\n<p>Microsoft follows the <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/cvd\" target=\"_blank\" rel=\"noreferrer noopener\">CVD principle<\/a> when partnering with external security researchers to respond and mitigate vulnerabilities in our products and services. This approach gives researchers recognition for their work\u2014and provides Microsoft an opportunity to address newly reported vulnerabilities before bad actors can exploit them.<\/p>\n<p>To better protect our products and services, MSRC partners with Microsoft engineering teams to build proactive mitigations using the information provided by both internal and external security researchers. This can significantly reduce or eliminate classes of vulnerabilities.<\/p>\n<p>Many of the cloud service vulnerabilities are fixed by Microsoft on our servers and don\u2019t require customers to take action to stay secure, but for purposes of transparency we now <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/06\/toward-greater-transparency-unveiling-cloud-service-cves\/\" target=\"_blank\" rel=\"noreferrer noopener\">disclose all critical cloud common vulnerabilities and exposures<\/a> (CVEs). In cases where Microsoft customers need to act, Microsoft provides customers with clear and timely security guidance.<\/p>\n<p>To help customers accelerate their security response and remediation, Microsoft recently expanded our CVD strategy to include machine-readable <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/11\/toward-greater-transparency-publishing-machine-readable-csaf-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">Common Security Advisory Framework (CSAF)<\/a> files that complement our existing CVD data sharing channels. With CSAF files, Microsoft customers now have machine-readable information on known vulnerabilities. This capability is part of our comprehensive strategy for vulnerability disclosure, which includes our <a href=\"https:\/\/github.com\/microsoft\/MSRC-Microsoft-Security-Updates-API\">Security Updates API<\/a> and the human-readable vulnerability disclosures provided in the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\" target=\"_blank\" rel=\"noreferrer noopener\">MSRC Security Update Guide<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"microsoft-active-protections-program-mapp\">Microsoft Active Protections Program (MAPP)<\/h2>\n<p>The <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/mapp\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Active Protections Program (MAPP<\/a>) gives security technology providers early access to vulnerability information so that they can more rapidly provide updated protections to their customers. More than 100 MAPP partners receive security vulnerability information from the MSRC in advance of Microsoft\u2019s monthly security update release. Partners use this information to provide protections through their security software or devices, such as antivirus software, network-based intrusion detection systems, or host-based intrusion prevention systems.<\/p>\n<p>To learn about the MAPP program, including which types of organizations are eligible to join MAPP, what is required of member organizations, and MAPP program tiers, read the <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/faqs-mapp\" target=\"_blank\" rel=\"noreferrer noopener\">MAPP Frequently Asked Questions<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"release-of-security-updates\">Release of security updates<\/h2>\n<p>Microsoft-managed backend services require no additional customer action to stay secure. In cases where customers must take action to stay secure, we release security updates.<\/p>\n<p>After a vulnerability that requires customers to take action has been fixed in our products, MSRC provides updates. MSRC releases security updates for most Microsoft products on the second Tuesday of each month at 10:00 AM PT and recommends that IT administrators and other customers plan their deployment schedules accordingly.<\/p>\n<h2 class=\"wp-block-heading\" id=\"cybersecurity-education-through-content-and-conferences\">Cybersecurity education through content and conferences<\/h2>\n<p>A key component of MSRC\u2019s work is to provide educational content for the security community. MSRC shares important public updates on vulnerabilities and more on the <a href=\"https:\/\/msrc.microsoft.com\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">MSRC blog<\/a> (you can also <a href=\"https:\/\/msrc.microsoft.com\/blog\/rss\/\" target=\"_blank\" rel=\"noreferrer noopener\">subscribe through the MSRC RSS feed<\/a>). The latest information about security-related deployments, known vulnerabilities, and advisories can be found on the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/deployments\" target=\"_blank\" rel=\"noreferrer noopener\">Security Update Guide<\/a>.<\/p>\n<p>MSRC also works to build a stronger security researcher community by hosting the <a href=\"https:\/\/www.microsoft.com\/bluehat\/\">BlueHat security conference<\/a>. BlueHat brings together leading researchers and security practitioners, providing a platform to share knowledge and best practices around security. If you missed the latest conference, you can view <a href=\"https:\/\/www.youtube.com\/@msftsecresponse\" target=\"_blank\" rel=\"noreferrer noopener\">on-demand presentations<\/a> from past conferences or <a href=\"https:\/\/thecyberwire.com\/podcasts\/the-bluehat-podcast\" target=\"_blank\" rel=\"noreferrer noopener\">listen to the BlueHat Podcast<\/a> (<a href=\"https:\/\/feeds.megaphone.fm\/the-bluehat-podcast\" target=\"_blank\" rel=\"noreferrer noopener\">subscribe here<\/a>).<\/p>\n<h2 class=\"wp-block-heading\" id=\"learn-more-about-the-microsoft-security-response-center\">Learn more about the Microsoft Security Response Center<\/h2>\n<p>To learn more about MSRC, visit us at <a href=\"https:\/\/msrc.microsoft.com\">msrc.microsoft.com<\/a>. There, you can find detailed information on our programs and access educational resources. You can also learn more about MSRC and Microsoft\u2019s related security initiatives through the following resources:<\/p>\n<p>To learn more about Microsoft Security solutions, visit our&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener\">website.<\/a>&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>)&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<p>READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/03\/13\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn about the Microsoft Security Response Center, which investigates vulnerabilities and releases security updates to help protect customers from cyberthreats.<br \/>\nThe post How MSRC coordinates vulnerability research and disclosure while building community appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":58294,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[],"class_list":["post-58293","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How MSRC coordinates vulnerability research and disclosure while building community 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How MSRC coordinates vulnerability research and disclosure while building community 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-13T16:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Security_1028749_Blog_250307.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"How MSRC coordinates vulnerability research and disclosure while building community\",\"datePublished\":\"2025-03-13T16:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/\"},\"wordCount\":945,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg\",\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/\",\"name\":\"How MSRC coordinates vulnerability research and disclosure while building community 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg\",\"datePublished\":\"2025-03-13T16:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How MSRC coordinates vulnerability research and disclosure while building community\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How MSRC coordinates vulnerability research and disclosure while building community 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/","og_locale":"en_US","og_type":"article","og_title":"How MSRC coordinates vulnerability research and disclosure while building community 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-03-13T16:00:00+00:00","og_image":[{"url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Security_1028749_Blog_250307.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"How MSRC coordinates vulnerability research and disclosure while building community","datePublished":"2025-03-13T16:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/"},"wordCount":945,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg","articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/","url":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/","name":"How MSRC coordinates vulnerability research and disclosure while building community 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg","datePublished":"2025-03-13T16:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community.jpg","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"How MSRC coordinates vulnerability research and disclosure while building community"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58293"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58293\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/58294"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58293"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58293"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}