Top MSRC 2020 Q4 Security Researchers – Congratulations!

Source: https://msrc-blog.microsoft.com/blog/2021/01/top-msrc-2020-q4-security-researchers-congratulations/ We’re excited to announce the top contributing researchers for the 2020 Fourth Quarter (Q4)! Congratulations to all of the researchers who made this quarter’s leaderboard and a huge thank you … Read more

Microsoft Internal Solorigate Investigation Update

Source: https://msrc-blog.microsoft.com/blog/2020/12/microsoft-internal-solorigate-investigation-update/ As we said in our recent blog, we believe the Solorigate incident is an opportunity to work together in important ways, to share information, strengthen defenses and respond to attacks. … Read more

Nobelium Resource Center – updated March 4, 2021

Source: https://msrc-blog.microsoft.com/blog/2020/12/december-21st-2020-solorigate-resource-center/ ** UPDATE: ** Microsoft continues to work with partners and customers to expand our knowledge of the threat actor behind the nation-state cyberattacks that compromised the supply chain of SolarWinds … Read more

Customer Guidance on Recent Nation-State Cyber Attacks

Source: https://msrc-blog.microsoft.com/blog/2020/12/customer-guidance-on-recent-nation-state-cyber-attacks/ Note: we are updating as the investigation continues. Revision history listed at the bottom. This post contains technical details about the methods of the actor we believe was involved in … Read more

Security Update Guide: Let's keep the conversation going

Source: https://msrc-blog.microsoft.com/blog/2020/12/security-update-guide-lets-keep-the-conversation-going/ Hi Folks, We want to continue to highlight changes we’ve made to our Security Update Guide. We have received a lot of feedback, much of which has been very positive. … Read more

Vulnerability Descriptions in the New Version of the Security Update Guide

Source: https://msrc-blog.microsoft.com/blog/2020/11/vulnerability-descriptions-in-the-new-version-of-the-security-update-guide/ With the launch of the new version of the Security Update Guide, Microsoft is demonstrating its commitment to industry standards by describing the vulnerabilities with the Common Vulnerability Scoring System … Read more

Attacks exploiting Netlogon vulnerability (CVE-2020-1472)

Source: https://msrc-blog.microsoft.com/blog/2020/10/attacks-exploiting-netlogon-vulnerability-cve-2020-1472/ Microsoft has received a small number of reports from customers and others about continued activity exploiting a vulnerability affecting the Netlogon protocol (CVE-2020-1472) which was previously addressed in security updates … Read more

Announcing the Top MSRC 2020 Q3 Security Researchers

Source: https://msrc-blog.microsoft.com/blog/2020/10/announcing-the-top-msrc-2020-q3-security-researchers/ Following the MSRC’s 2020 Most Valuable Security Researchers announced during this year’s Black Hat, we’re excited to announce the top contributing researchers for the 2020 Third Quarter (Q3)! The top … Read more

Security Analysis of CHERI ISA

Source: https://msrc-blog.microsoft.com/blog/2020/10/security-analysis-of-cheri-isa/ Is it possible to get to a state where memory safety issues would be deterministically mitigated? Our quest to mitigate memory corruption vulnerabilities led us to examine CHERI (Capability Hardware … Read more