Microsoft Joins Open Source Security Foundation

Posted on Monday August 03, 2020  |  MSRC alerts

Microsoft has invested in the security of open source software for many years and today I'm excited to share that Microsoft is joining industry partners to create the Open Source Security Foundation (OpenSSF), a new cross-industry collaboration hosted at the Linux Foundation. The OpenSSF brings together work from the Linux Foundation-initiated Core Infrastructure Initiative (CII)...

 

Black Hat 2020: See you in the Cloud!

Posted on Thursday July 30, 2020  |  MSRC alerts

It hardly feels like summer without the annual trip to Las Vegas for Black Hat USA. With this year's event being totally cloud based, we won't have the chance to catch up with security researchers, industry partners, and customers in person, an opportunity we look forward to every year. We'll still be there though, and...

 

Updates to the Windows Insider Preview Bounty Program

Posted on Friday July 24, 2020  |  MSRC alerts

Partnering with the research community is an important part of Microsoft's holistic approach to defending against security threats. Bounty programs are one part of this partnership, designed to encourage and reward vulnerability research focused on the highest impact to customer security. The Windows Insider Preview (WIP) Bounty Program is a key program for Microsoft and...

 

Top MSRC 2020 Q2 Security Researchers Announced — Congratulations!

Posted on Wednesday July 15, 2020  |  MSRC alerts

We are excited to announce the top contributing researchers for the 2020 Second Quarter (Q2)! Congratulations to all the researchers who continue to rock the leaderboard, and a big thank you to everyone for your contribution to securing our customers and the ecosystem. The top three researchers of the 2020 Second Quarter (Q2) Security Researcher...

 

July 2020 Security Update: CVE-2020-1350 Vulnerability in Windows Domain Name System (DNS) Server

Posted on Tuesday July 14, 2020  |  MSRC alerts

Today we released an update for CVE-2020-1350, a Critical Remote Code Execution (RCE) vulnerability in Windows DNS Server that is classified as a 'wormable' vulnerability and has a CVSS base score of 10.0. This issue results from a flaw in Microsoft's DNS server role implementation and affects all Windows Server versions. Non-Microsoft DNS Servers are not affected. Wormable vulnerabilities have the potential to spread via malware between vulnerable computers without user interaction. Windows DNS Server is a core networking component. While this...

 

Solving Uninitialized Kernel Pool Memory on Windows

Posted on Thursday July 02, 2020  |  MSRC alerts

This blog post outlines the work that Microsoft is doing to eliminate uninitialized kernel pool memory vulnerabilities from Windows and why we’re on this path. For a background on why uninitialized memory matters and what options have been used in the past to tackle this issue, please see our previous blog post. The brief recap...

 

Page:   1...101112131415161718...31

Celebrating 35+ Years

Managed Computer Support Services

Contact Us

Support Ends for Windows 10 22H2, Windows Server 2012 R2, Exchange 2013, Office 2016