Microsoft has announced a strategic initiative to eliminate all C and C++ code from its software portfolio by 2030, aiming to rewrite its codebase in the memory-safe language Rust. The company is leveraging a combination of AI and advanced algorithms to automate the translation of legacy code, with the goal of enabling a single engineer to convert up to one million lines of code in a month. This effort is supported by the development of new internal tools and the recruitment of specialized engineers to drive the transition, as detailed by Microsoft distinguished engineer Galen Hunt.
The move to Rust is motivated by the language's inherent memory safety features, which help prevent vulnerabilities such as out-of-bounds reads, writes, and use-after-free errors—common attack vectors in C and C++ applications. Microsoft’s leadership has publicly advocated for the adoption of memory-safe languages to reduce technical debt and improve software security, aligning with broader industry and governmental calls for safer software development practices.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft said it will use AI and algorithmic tooling to automate translation of C and C++ code into Rust at scale, with a stated ambition of enabling one engineer to rewrite one million lines of code per month. The company also noted it has already built infrastructure for large-scale code processing and is hiring engineers to expand these capabilities.
Microsoft announced a long-term initiative to phase out C and C++ across its codebase by 2030 and replace them with Rust to improve security and reliability through memory-safe software development. Multiple reports describe this as a major strategic shift affecting Microsoft's broader software estate.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.