Concluding the Azure Sphere Security Research Challenge, Microsoft Awards $374,300 to Global Security Research Community

Source: https://msrc-blog.microsoft.com/blog/2020/10/azure-sphere-security-research-challenge-concluded/ The Azure Sphere Security Research Challenge brought together 70 researchers from 21 countries to help secure Azure Sphere customers and expand Microsoft’s partnerships with the global IoT security research community. … Read more

New and improved Security Update Guide!

Source: https://msrc-blog.microsoft.com/blog/2020/09/new-and-improved-security-update-guide/ We’re excited to announce a significant update to the Security Update Guide, our one-stop site for information about all security updates provided by Microsoft. This new version will provide a … Read more

What to Expect When Reporting Vulnerabilities to Microsoft

Source: https://msrc-blog.microsoft.com/blog/2020/09/what-to-expect-when-reporting-vulnerabilities-to-microsoft/ At the Microsoft Security Response Center’s (MSRC), our primary mission is to help protect our customers. One of the ways we do this is by working with security researchers to … Read more

Control Flow Guard for Clang/LLVM and Rust

Source: https://msrc.microsoft.com/blog/2020/08/control-flow-guard-for-clang-llvm-and-rust/ As part of our ongoing efforts towards safer systems programming, we’re pleased to announce that Windows Control Flow Guard (CFG) support is now available in the Clang C/C++ compiler and … Read more

DUO-PSA-2020-004: Duo Product Security Advisory

Duo Product Security Advisory Advisory ID: DUO-PSA-2020-004 CVE: CVE-2020-3483 Publication Date: 2020-08-13 Revision Date: 2020-08-13 Status: Confirmed, Fixed Document Revision: 1 Overview Duo has identified and fixed an issue with the Duo … Read more

Microsoft Joins Open Source Security Foundation

Source: https://msrc.microsoft.com/blog/2020/08/microsoft-joins-open-source-security-foundation/ Microsoft has invested in the security of open source software for many years and today I’m excited to share that Microsoft is joining industry partners to create the Open Source … Read more

Black Hat 2020: See you in the Cloud!

Source: https://msrc.microsoft.com/blog/2020/07/black-hat-2020-see-you-in-the-cloud/ It hardly feels like summer without the annual trip to Las Vegas for Black Hat USA. With this year’s event being totally cloud based, we won’t have the chance to … Read more

Updates to the Windows Insider Preview Bounty Program

Source: https://msrc.microsoft.com/blog/2020/07/updates-to-the-windows-insider-preview-bounty-program/ Partnering with the research community is an important part of Microsoft’s holistic approach to defending against security threats. Bounty programs are one part of this partnership, designed to encourage and … Read more

DUO-PSA-2020-003: Duo Product Security Advisory

Duo Product Security Advisory Advisory ID: DUO-PSA-2020-003 Publication Date: 2020-06-30 Revision Date: 2020-06-30 Status: Confirmed, Fixed Document Revision: 2 Overview Duo has identified and fixed an issue in the Duo Connect client … Read more

Azure Sphere Security Research Challenge Now Open

Source: https://msrc.microsoft.com/blog/2020/05/azure-sphere-security-research-challenge/ The Azure Sphere Security Research Challenge is an expansion of Azure Security Lab, announced at Black Hat in August 2019. At that time, a select group of talented researchers was … Read more

The Safety Boat: Kubernetes and Rust

Source: https://msrc.microsoft.com/blog/2020/04/the-safety-boat-kubernetes-and-rust/ Our team, DeisLabs, recently released a new piece of software called Krustlet, which is a tool for running WebAssembly modules on the popular, open-source container management tool called Kubernetes. Kubernetes … Read more

DUO-PSA-2020-002: Duo Product Security Advisory

Duo Product Security Advisory Advisory ID: DUO-PSA-2020-002 Publication Date: 2020-04-28 Revision Date: 2020-04-28 Status: Confirmed, Fixed Document Revision: 1 Overview Duo Engineering has identified and fixed an issue with directory sync for … Read more

Congratulating Our Top 2020 Q1 Security Researchers!

Source: https://msrc.microsoft.com/blog/2020/04/msrc-q1-2020-leaderboard/ Following the second Security Researcher Quarterly Leaderboard and the 2020 MSRC Most Valuable Security Researchers criteria we published in February 2020, we are excited to announce the 2020 First Quarter … Read more

DUO-PSA-2020-001: Duo Product Security Advisory

Duo Product Security Advisory Advisory ID: DUO-PSA-2020-001 Publication Date: 2020-03-19 Revision Date: 2020-03-19 Status: Confirmed, Fixed Document Revision: 1 Overview Duo has identified and fixed an issue with Directory Sync where enrollment … Read more

March 2020 security updates are available

Source: https://msrc.microsoft.com/blog/2020/03/march-2020-security-updates-are-available/ We have released the March security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this … Read more