Agentic Security Leader @ Microsoft & Security Researcher

David Weston

David Weston leads Agentic Security at Microsoft, where he builds the AI models, autonomous agents, and evaluation systems redefining how defenders operate. At Microsoft since the Windows 7 era, he has worked across exploit mitigation design, malware analysis, APT research, and led security engineering for Windows, Xbox, Azure OS, and Microsoft's Offensive Security Research & Engineering group. His current work is leading teams training frontier security models, agentic security systems for defenders, and pushing AI-driven vulnerability discovery through Microsoft's Multi-Model Agentic Scanning Harness (MDASH). A longtime member of the research community and former CISA technical advisor, David is a regular presenter at BlueHat, Black Hat, and DEF CON.

Jan 15, 2025

AI at the Edge: Attacks and Defense

BlueHat India 2025 Day 1 Keynote covering AI security at the edge, including attack vectors and defensive strategies.

bluehat AI security edge computing keynote

Oct 11, 2024

CISA CSAC Technical Advisory Council: Open Source Security Recommendations

Recommendations on improving security in critical open source projects and advancing CISA's secure by design initiative, addressing unique challenges in open source software ecosystems.

CISA open source policy technical advisory secure by design

Oct 03, 2024

A sneak peek into Microsoft's Windows 2030 vision

A sneak peek into what's next for Windows and how AI is shaping the future of the OS.

windows future ai

NBC's Today Show - Jul 04, 2018

NBC Today show segment

ITV News UK - Nov 25, 2017

ITV News UK segment

Infosecurity Magazine - Jul 27, 2026

Microsoft Launches Flurry of AI Security Initiatives

December 09, 2025

Coming Soon

New content is on the way. Check back soon for updates on platform security, research, and more.

What to expect

Field notes on platform security, adversary tradecraft, and the mechanics of running resilient security programs.

About

I lead Agentic Security at Microsoft, where I build the AI models, autonomous agents, and evaluation systems redefining how defenders operate. My current work spans training frontier security models, building agentic security systems for defenders, and pushing AI-driven vulnerability discovery through Microsoft's Multi-Model Agentic Scanning Harness (MDASH). I share what we learn so the broader community can raise the bar together.

My background spans vulnerability research, exploit mitigations, red teaming, and building product security programs that survive contact with reality. If you're working on hard security problems, I'd love to compare notes.

David Weston headshot