Loading...

Securing Redirections with Mike Macelletti

Securing Redirections with Mike Macelletti

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by Mike Macelletti from Microsoft’s MSRC Vulnerabilities and Mitigations team to explore Redirection Guard, a powerful mitigation designed to tackle a long-standing class of file path redirection vulnerabilities in Windows. Mike shares how his interest in security began, the journey behind developing Redirection Guard, and how it's helping reduce a once-common bug class across Microsoft products. He also explains how the feature works, why it's impactful, and what developers can do to adopt it. Plus, a few fun detours into Solitaire hacking, skiing, and protein powder.   In This Episode You Will Learn:   What Redirection Guard is and how it helps prevent file system vulnerabilities How Microsoft identifies and addresses common bug classes across their ecosystem Why some vulnerabilities still slip past Redirection Guard and what’s out of scope  Some Questions We Ask:  What is a junction and how is it different from other redirects? How does Redirection Guard decide which shortcuts to block? Are there vulnerabilities Redirection Guard doesn’t cover?      Resources:      View Mike Macelletti on LinkedIn     View Wendy Zenone on LinkedIn   View Nic Fillingham on LinkedIn     Related Microsoft Podcasts:     Microsoft Threat Intelligence Podcast   Afternoon Cyber Tea with Ann Johnson   Uncovering Hidden Risks       Discover and follow other Microsoft podcasts at microsoft.com/podcasts    Hosted on Acast. See acast.com/privacy for more information.

Published on:

Learn more
Need help with this product?

We can help you with Securing Redirections with Mike Macelletti

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

Security Unlocked
Security Unlocked

Security Unlocked explores the technology and people powering Microsoft's Security solutions. In each episode, Microsoft Security evangelists Nic Fillingham and Natalia Godyla take a closer look at the latest innovations in threat intelligence, security research, and data science, with a special focus on demystifying artificial intelligence and machine learning. Be sure to listen in and follow us!

Share post:

Related posts

Hunting Variants: Finding the Bugs Behind the Bug

In this episode of The BlueHat Podcast, host Nic Fillingham is joined by George Hughey from Microsoft who returns to discuss his Blue Hat Indi...

1 year ago

Ignore Ram Shankar Siva Kumar’s Previous Directions

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone share Ram Shankar Siva Kumar’s dynamic keynote from BlueHat India...

1 year ago

Protecting AI at the Edge with David Weston

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone share David Weston’s keynote from BlueHat India 2025. David explo...

1 year ago

Hacking at the Weeds with Felix Boulet

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by Felix Boulet fresh off his participation in Zero Da...

1 year ago

Evolutions in Hacking with Marco Ivaldi

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by Marco Ivaldi, co-founder and technical director of ...

1 year ago

From Facebook-phished to MVR Top 5 with Dhiral Patel

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by Dhiral Patel, Senior Security Engineer at ZoomInfo ...

1 year ago

AI & the Hunt for Hidden Vulnerabilities with Tobias Diehl

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by security researcher Tobias Diehl, a top contributor...

1 year ago

Cryptojacking, and Farewell for Now!

This episode of Security Unlocked delves into the world of cryptocurrency and the prevalence of cryptojacking. Hosts Natalia Godyla and Nic Fi...

4 years ago

A look at Cybercrime in 2021

This episode of Security Unlocked takes a deep dive into the growing threat of cybercrime in 2021. Ransomware attacks in particular have becom...

4 years ago

What’s a BISO?

In this episode of Security Unlocked, S&P Global Ratings BISO Alyssa Miller shares her journey from being a curious young hacker to becoming a...

4 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.