attacks

  1. Microsoft Security Advisory (2718704): Unauthorized Digital Certificates Could Allow Spoofing - Vers

    Revision Note: V1.0 (June 3, 2012): Advisory published. Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived by a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or...
  2. No OS Is an Island

    Mac Users Now Also Susceptible to Targeted Attacks | Malware Blog | Trend Micro
  3. Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation

    Revision Note: V1.3 (November 8, 2011): Added link to MAPP Partners with Updated Protections in the Executive Summary. Revised impact statement for the workaround, Deny access to T2EMBED.DLL, to address a reoffer issue on Windows XP and Windows Server 2003. Also, revised the mitigating factors...
  4. Microsoft Security Advisory (974926): Credential Relaying Attacks on Integrated Windows Authenticati

    Revision Note: V1.0 (December 8, 2009): Advisory published. Summary: This advisory addresses the potential for attacks that affect the handling of credentials using Integrated Windows Authentication (IWA), and the mechanisms Microsoft has made available for customers to help protect...
  5. Microsoft Security Advisory (2264072): Elevation of Privilege Using Windows Service Isolation Bypass

    Revision Note: V1.0 (August 10, 2010): Advisory published. Summary: Microsoft is aware of the potential for attacks that leverage the Windows Service Isolation feature to gain elevation of privilege. This advisory discusses potential attack scenarios and provides suggested actions that...
  6. Microsoft Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing - Versio

    Revision Note: V3.0 (September 6, 2011): Revised to announce the release of an update that addresses this issue. Summary: Microsoft is aware of active attacks using at least one fraudulent digital certificate issued by DigiNotar, a certification authority present in the Trusted Root...
  7. Microsoft Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing - 9/6/20

    Revision Note: V3.0 (September 6, 2011): Revised to announce the release of an update that addresses this issue. Advisory Summary:Microsoft is aware of active attacks using at least one fraudulent digital certificate issued by DigiNotar, a certification authority present in the Trusted Root...
  8. Windows 7 Cybercrime or Cyberwar?

    America's Cybercrime Risk - A Look at Articles on Information Management and National Security
  9. Windows 7 LulzSec calls on everyone to attack government assets

    LulzSec has launched a new hacking campaign dubbed Operation Anti-Security and calls on everyone, supporters and enemies alike, to attack Web sites belonging to any government agency or government-friendly organization This sounds very serious. Banks and large corporations seem to be their...
  10. Microsoft Security Advisory (2524375): Fraudulent Digital Certificates Could Allow Spoofing

    Revision Note: V2.0 (April 19, 2011): Added Windows Mobile 6.x, Windows Phone 7, Microsoft Kin, and Zune devices to affected software and devices.Summary: Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root...
  11. Coordinated Vulnerability Disclosure: From Philosophy to Practice

    Last summer at the Black Hat security conference, we announced a philosophical shift in how we refer to vulnerability disclosure, called "Coordinated Vulnerability Disclosure" (CVD). Our intent was to focus on how coordination and collaboration are required to resolve security issues in a way...
  12. Microsoft Security Advisory (2501696): Vulnerability in MHTML Could Allow Information Disclosure - 3

    Revision Note: V1.1 (March 11, 2011): Revised Executive Summary to reflect investigation of limited, targeted attacks. Advisory Summary:Microsoft has completed the investigation into public reports of this vulnerability. We have issued MS11-026 to address this issue. For more information about...
  13. B

    Windows Vista vista 2010/2011: trojan nasty little mutha!

    Just a line to see if anyone has encounterd ,that internet nasty vista 2011 malware remover,that is a trojan,that attaches itself to windows secdurity center, or pretends to be windows security center, and begins to warn through various false scans and notices, of attacks and spyware ,and all...
  14. Microsoft Security Advisory (2488013): Vulnerability in Internet Explorer Could Allow Remote Code Ex

    Revision Note: V1.3 (January 11, 2011): Revised the workaround, Prevent the recursive loading of CSS style sheets in Internet Explorer, to add the impact for the workaround.Summary: Microsoft is investigating new, public reports of limited attacks attempting to exploit a vulnerability in all...
  15. Microsoft Security Advisory (2488013): Vulnerability in Internet Explorer Could Allow Remote Code Ex

    Revision Note: V1.2 (January 11, 2011): Added the workaround, Prevent the recursive loading of CSS style sheets in Internet Explorer, and revised Executive Summary to reflect investigation of limited attacks. Advisory Summary:Microsoft is investigating new, public reports of targeted attacks...
  16. Black Hat 2010

    BH Landscape Next week, many of us here will be heading down to Las Vegas for Black Hat. The MSRC, and other teams in Microsoft, have been attending Black Hat for years. In fact, we've been sponsoring the show for the last eight years-the last five as a platinum sponsor. Some might ask why...
  17. Microsoft Security Advisory 2269637 Released

    Overview Today we released MicrosoftLink Removed due to 404 Error. This is different from other Microsoft Security Advisories because it's not talking about specific vulnerabilities in Microsoft products. Rather, this is our official guidance in response to security research that has outlined a...
  18. Update to Security Advisory 2416728

    Hi everyone - We've just updated Link Removed due to 404 Error as we've begun to see limited attacks with the ASP.NET vulnerability. We have added questions and answers and encourage customers to review this information and evaluate it for their environment. We have also added additional...
  19. Microsoft Security Advisory (2264072): Elevation of Privilege Using Windows Service Isolation Bypass

    Revision Note: V1.0 (August 10, 2010): Advisory published.Summary: Microsoft is aware of the potential for attacks that leverage the Windows Service Isolation feature to gain elevation of privilege. This advisory discusses potential attack scenarios and provides suggested actions that can help...
  20. Microsoft Security Advisory (2264072): Elevation of Privilege Using Windows Service Isolation Bypass

    Revision Note: V1.0 (August 10, 2010): Advisory published.Summary: Microsoft is aware of the potential for attacks that leverage the Windows Service Isolation feature to gain elevation of privilege. This advisory discusses potential attack scenarios and provides suggested actions that can help...