Introducing the Microsoft Defender Bounty Program

Source: https://msrc.microsoft.com/blog/2023/11/introducing-the-microsoft-defender-bounty-program/ We are excited to announce the new Microsoft Defender Bounty Program with awards of up to $20,000 USD. The Microsoft Defender brand encompasses a variety of products and services designed … Read more

Reflecting on 20 years of Patch Tuesday

Source: https://msrc.microsoft.com/blog/2023/11/reflecting-on-20-years-of-patch-tuesday/ This year is a landmark moment for Microsoft as we observe the 20th anniversary of Patch Tuesday updates, an initiative that has become a cornerstone of the IT world’s approach … Read more

Microsoft guidance regarding credentials leaked to GitHub Actions Logs through Azure CLI

Source: https://msrc.microsoft.com/blog/2023/11/microsoft-guidance-regarding-credentials-leaked-to-github-actions-logs-through-azure-cli/ Summary Summary The Microsoft Security Response Center (MSRC) was made aware of a vulnerability where Azure Command-Line Interface (CLI) could expose sensitive information, including credentials, through GitHub Actions logs. The … Read more

Congratulations to the Top MSRC 2023 Q3 Security Researchers!

Source: https://msrc.microsoft.com/blog/2023/10/congratulations-to-the-top-msrc-2023-q3-security-researchers/ Congratulations to all the researchers recognized in this quarter’s Microsoft Researcher Recognition Program leaderboard! Thank you to everyone for your hard work and continued partnership to secure customers. The top … Read more

Microsoft Response to Distributed Denial of Service (DDoS) Attacks against HTTP/2

Source: https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/ Summary Summary Beginning in September 2023, Microsoft was notified by industry partners about a newly identified Distributed Denial-of-Service (DDoS) attack technique being used in the wild targeting HTTP/2 protocol. This … Read more

Cybersecurity Awareness Month 2023: Elevating Security Together

Source: https://msrc.microsoft.com/blog/2023/10/cybersecurity-awareness-month-2023-elevating-security-together/ As the 20th anniversary of Cybersecurity Awareness Month begins, I find myself reflecting on the strides made since its inception. The journey to enhance and improve cybersecurity is ongoing and extends … Read more

Microsoft’s Response to Open-Source Vulnerabilities – CVE-2023-4863 and CVE-2023-5217

Source: https://msrc.microsoft.com/blog/2023/10/microsofts-response-to-open-source-vulnerabilities-cve-2023-4863-and-cve-2023-5217/ Microsoft is aware and has released patches associated with the two Open-Source Software security vulnerabilities, CVE-2023-4863 and CVE-2023-5217. Through our investigation, we found that these affect a subset of our … Read more