Cam
@SecretlyHidden1
Followers
2K
Following
459
Media
5
Statuses
206
Former full time bug bounty hunter - now doing security stuff at places :)
Joined October 2015
In our latest blog, Cameron Vincent (@SecretlyHidden1), Senior Security Researcher at MSRC, features the work of MSRC intern and security researcher, Brian McNulty (@brianjmcnulty), who uncovered 22+ critical vulnerabilities in just two months. Learn how the MSRC team leverages
1
7
36
At BlueHat Asia, Cameron Vincent (@SecretlyHidden1), Senior Security Researcher, Microsoft, and Brian McNulty (@brianjmcnulty), MSRC Summer Intern and University of Michigan graduate student, shared their journey hunting security variants across the Microsoft ecosystem.
4
6
15
We hosted a pre-BlueHat Asia welcome reception this evening, giving our speakers, MSRC MVRs, and Microsoft team members a great opportunity to connect. A huge thank you to our presenters and MVRs for their role in making #BlueHatAsia a success! We can’t wait to kick off BlueHat
0
11
31
We’re excited to announce our next BlueHat Asia speakers: Brian McNulty (@brianjmcnulty) and Cameron Vincent (@SecretlyHidden1)! Cameron is a Senior Security Researcher at Microsoft, specializing in vulnerabilities and mitigation within MSRC. From reproducing bug reports to
0
4
14
My first 10.0 CVE ;)
[1/7] 🚨 @Microsoft just patched CVE-2025-29813, a severe Azure DevOps vulnerability with a perfect CVSS score of 10.0! This flaw allowed attackers to swap short-term pipeline tokens for long-term ones, potentially extending their access. No user action needed. @AzureDevOps
32
68
2K
@Microsoft @AzureDevOps @msftsecurity @VisualStudio @msftsecresponse [5/7] 🛡️ MITIGATION: Microsoft states "This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take." The fix corrects how the Visual Studio updater handles pipeline tokens. Credit to Cameron Vincent at Microsoft for this
1
1
8
If you wanna see some interesting Google vulns I found my Nullcon talk covers them ;) Shoutout the @GoogleVRP team!
Ever edited someone else’s app on Google Play? 😳 @SecretlyHidden1 did — and got rewarded for it 💰 At #NullconGoa2025, he broke down exactly how he hacked the Google Bug Bounty Program and climbed to the top of the leaderboard 👉 https://t.co/TgdbcYVHk8
#bughunting #google
2
1
18
I’m horrible at photos but here are some from the event at the space needle and mariners game! Again truly amazing event and look forward to future research from everyone! @msftsecresponse thank you for including me!
0
0
5
Now that the smoke has settled wanted to tweet about the amazing Zero Day Quest event the @msftsecresponse held. The planning, coordination, and effort all the teams put into making it an amazing event for our top researchers was truly admirable. It was great seeing everyone!
0
0
2
We had a wonderful evening connecting with some of the incredible security researchers participating in the Microsoft Zero Day Quest Onsite Hacking Event. It’s always inspiring to meet those who dedicate their skills to uncovering and reporting critical vulnerabilities—whether
1
5
46
🚀 Bug bounty hunters, this one’s for you! @SecretlyHidden1, Security Engineer, Microsoft is on stage at #NullconGoa2025. From hunting down vulnerabilities in Google's vast ecosystem to the art of responsible disclosure, this session is packed with jaw-dropping security finds.
0
3
18
Cameron Vincent @SecretlyHidden1, Security Researcher at Microsoft, gave a talk about IDOR vulnerabilities to a packed room at @nullcon #Goa. Cameron discussed how broken access control has been the top problem across the ecosystem for a while. Camerons research into IDOR
0
4
29
This week's Patch Tuesday included 8 CVEs that @rohitwas and I found! We've been focusing on findings ways to bypass MapUrlToZone and found several very interesting ways to confuse it. This is an API we've seen a lot of interest in lately, so good to have it locked down!
2
3
43
Join MSRC and special guest Scott Gorlick, Principal Security Architect at Microsoft, next week for a virtual session on Security Research in Copilot Studio. The Copilot ecosystem allows enterprises to develop Copilot Agents using resources and integrations that span services in
3
20
28
Shoutout to the @GoogleVRP as well! They were amazing to work with and fixed everything quickly! I’m excited to share some of my techniques for hunting on Google.
Ever wonder how it was possible to edit other user's apps on the Google Play store? 🤔 Join @SecretlyHidden1 at #NullconGoa2025 and discover how to hunt for authorization and logic vulnerabilities across multiple Google products. 👉 https://t.co/yRHsgUzPnZ
#Google #bugbounty
0
1
20
Ever wonder how it was possible to edit other user's apps on the Google Play store? 🤔 Join @SecretlyHidden1 at #NullconGoa2025 and discover how to hunt for authorization and logic vulnerabilities across multiple Google products. 👉 https://t.co/yRHsgUzPnZ
#Google #bugbounty
0
3
14
Excited to announce that I’ll be presenting @nullcon this year about research I did on the @GoogleVRP program. I will be disclosing some of my top findings and provide some tips to help researchers find similar types of bugs :) look forward to seeing everyone!
4
6
88
2/ Security is our top priority, and today we’re building on that commitment with Zero Day Quest, a new hacking event with $4 million in rewards focused on securing cloud and AI—the highest of any public hacking event in the industry: https://t.co/H2CDn9J1sr
3
24
182
As part of our Secure Future Initiative and to further the security of our customers, ourselves, and the world, today we are introducing the most transparent security research event in history: The Zero Day Quest. This new hacking event will be the largest of its kind, with an
6
61
139