As you’d expect, Microsoft invests significant resources on internal security processes like SDL, threat intelligence, red and blue teams, etc to protect products and customers. Another element is the large bug bounty program run by the Microsoft Security Response Center (MSRC). Periodically we in MSRC share with the public common bug patterns and mitigations strategies within Microsoft. In this talk we’d like to illuminate security researchers and customers on the most common web and cloud vulnerabilities fixed by MSRC. We’ll also talk about some of the mitigation strategies we’re using in this space. We’ll dive deep into novel SSRF variants, and show finders how to understand and search for these nasty critters.