February 2020 security updates are available

Source: https://msrc.microsoft.com/blog/2020/02/february-2020-security-updates-are-available/ We have released the February security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this … Read more

Recognizing Security Researchers in 2020

Source: https://msrc.microsoft.com/blog/2020/02/recognizing-security-researchers-in-2020/ Is it too early to talk about the 2020 MSRC Most Valuable Security Researchers? Five months from now, at the end of June, the program period closes for researchers to … Read more

Announcing the Xbox Bounty program

Source: https://msrc.microsoft.com/blog/2020/01/announcing-the-xbox-bounty-program/ We are pleased to announce the launch of the Xbox Bounty program today. The Xbox bounty program invites gamers, security researchers, and technologists around the world to help identify security … Read more

Announcing MSRC 2019 Q4 Security Researcher Leaderboard

Source: https://msrc.microsoft.com/blog/2020/01/msrc-q4-2019-leaderboard/ Following the first Security Researcher Quarterly Leaderboard we published in October 2019, we are excited to announce the MSRC Q4 2019 Security Researcher Leaderboard, which shows the top contributing researchers … Read more

January 2020 security updates are available!

Source: https://msrc.microsoft.com/blog/2020/01/january-2020-security-updates-are-available/ We have released the January security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this … Read more

January 2020 Security Updates: CVE-2020-0601

Source: https://msrc.microsoft.com/blog/2020/01/january-2020-security-updates-cve-2020-0601/ The January security updates include several Important and Critical security updates. As always, we recommend that customers update their systems as quickly as practical. Details for the full set of … Read more

Announcing the Microsoft Identity Research Project Grant

Source: https://msrc.microsoft.com/blog/2020/01/announcing-the-microsoft-identity-research-project-grant/ We are excited to announce the Microsoft Identity Research Project Grant a new opportunity in partnership with the security community to help protect Microsoft customers. This project grant awards up … Read more

December 2019 security updates are available

Source: https://msrc.microsoft.com/blog/2019/12/december-2019-security-updates-are-available/ We have released the December security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this … Read more

Customer Guidance for the Dopplepaymer Ransomware

Source: https://msrc.microsoft.com/blog/2019/11/customer-guidance-for-the-dopplepaymer-ransomware/ Microsoft has been investigating recent attacks by malicious actors using the Dopplepaymerransomware. There is misleading information circulating about Microsoft Teams, along with references to RDP (BlueKeep), as ways in which … Read more

DUO-PSA-2019-002: Duo Product Security Advisory

Duo Product Security Advisory Advisory ID: DUO-PSA-2019-002 CVE: CVE-2019-3465 Publication Date: 2019-11-12 Revision Date: 2019-11-12 Status: Confirmed, Fixed Document Revision: 1 Overview A third-party software library, which the Duo Access Gateway (DAG) … Read more

November 2019 security updates are available!

Source: https://msrc.microsoft.com/blog/2019/11/november-2019-security-updates-are-available/ We have released the November security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this … Read more

Using Rust in Windows

Source: https://msrc.microsoft.com/blog/2019/11/using-rust-in-windows/ This Saturday 9th of November, there will be a keynote from Microsoft engineers Ryan Levick and Sebastian Fernandez at RustFest Barcelona. They will be talking about why Microsoft is exploring … Read more

Vulnerability hunting with Semmle QL: DOM XSS

Source: https://msrc.microsoft.com/blog/2019/11/vulnerability-hunting-with-semmle-ql-dom-xss/ In two previous blog posts ( part 1 and part 2), we talked about using Semmle QL in C and C++ codebases to find vulnerabilities such as integer overflow, path … Read more

Time for day 2 of briefings at BlueHat Seattle!

Source: https://msrc.microsoft.com/blog/2019/10/time-for-day-2-of-briefings-at-bluehat-seattle/ We hope you enjoyed the first day of our BlueHat briefings and the Bytes of BlueHat reception in our glamping tent (complete with toasted marshmallows). Yesterday, we learned a lot … Read more

Welcome to the second stage of BlueHat!

Source: https://msrc.microsoft.com/blog/2019/10/welcome-to-the-second-stage-of-bluehat/ We’ve finished two incredible days of security trainings at the Living Computer Museum in Seattle. Now it’s time for the second part of BlueHat: the briefings at ShowBox SoDo. We’ve … Read more

Microsoft Identity Bounty Improvements

Source: https://msrc.microsoft.com/blog/2019/10/microsoft-identity-bounty-improvements/ Microsoft is continually improving our existing bounty programs. Today we’re happy to share the latest updates to the Microsoft Identity Bounty. Originally launched in July 2018, the Microsoft Identity bounty … Read more

Introducing the ElectionGuard Bounty program

Source: https://msrc.microsoft.com/blog/2019/10/introducing-the-electionguard-bounty-program/ Today we are launching the [ElectionGuard Bounty program](«http://www.microsoft.com/msrc/bounty-electionguard> >). In May 2019, we announced the release of ElectionGuard, a free open-source SDK to make voting more secure, transparent, and accessible. … Read more

Announcing the Security Researcher Quarterly Leaderboard

Source: https://msrc.microsoft.com/blog/2019/10/msrc-q3-2019-leaderboard/ Right before Black Hat USA 2019, we announced our new researcher recognition program, and at Black Hat we announced the top researchers from the previous twelve months. Since it’s easier … Read more

An intern's experience with Rust

Source: https://msrc.microsoft.com/blog/2019/10/an-interns-experience-with-rust/ Over the course of my internship at the Microsoft Security Response Center (MSRC), I worked on the safe systems programming languages (SSPL) team to promote safer languages for systems programming … Read more

October 2019 security updates are available!

Source: https://msrc.microsoft.com/blog/2019/10/october-2019-security-updates-are-available/ We have released the October security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this … Read more