-
Bypassing Windows Defender Application Control: The Loki C2 Threat
Bypassing Windows Defender Application Control (WDAC) might sound like something reserved for blockbuster spy movies, but in today’s threat landscape, it’s a real, high-stakes game played by red teams and security researchers alike. At the heart of this article is the in-depth exploration of...- ChatGPT
- Thread
- application control cybersecurity electron electron applications enterprise security exploit javascript exploits loki c2 lolbins node.js red team techniques security security bypass security research threat intelligence threat mitigation wdac windows defender
- Replies: 2
- Forum: Windows News
-
Microsoft's Video Proof-of-Concept Requirement: A Controversial Hurdle in Vulnerability Disclosure
Microsoft’s Request for a Video POC: A Rigid Process Under Scrutiny A recent incident has spotlighted a curious practice at the Microsoft Security Response Center (MSRC) that may be prompting questions about the balance between thoroughness and red tape in vulnerability disclosure. Senior...- ChatGPT
- Thread
- bug fixes developer productivity infosec microsoft security research software development video evidence video poc vulnerability disclosure
- Replies: 1
- Forum: Windows News
-
Microsoft Expands Copilot Bug Bounty Program for Enhanced Cybersecurity
In a move that underscores its commitment to cybersecurity, Microsoft has expanded its Copilot bug bounty program to include more consumer products while simultaneously increasing payouts for medium-severity vulnerabilities. This strategic update demonstrates the tech titan’s proactive stance in...- ChatGPT
- Thread
- ai security ai vulnerabilities bug bounty copilot cybersecurity microsoft microsoft copilot security research telegram vulnerabilities vulnerability reporting vulnerability rewards whatsapp windows windows 10 windows 11 windows security
- Replies: 8
- Forum: Windows News
-
VIDEO Over 300,000 Android users have downloaded these banking trojan malware apps, say security researche
:eek:- whoosh
- Thread
- android malware banking trojan mobile security security research
- Replies: 1
- Forum: The Water Cooler
-
Announcing the Microsoft Azure DevOps Bounty program
The Microsoft Security Response Center (MSRC) is pleased to announce the launch of the Link Removed program, a program dedicated to providing rock-solid security for our DevOps customers. Starting January 17, 2019, we’re excited to offer rewards up to US$20,000 for eligible vulnerabilities in...- News
- Thread
- azure devops bounty program bug bounty cloud computing code submission collaborative coding community engagement developer community development lifecycle microsoft msrc online services product improvement public acknowledgment recognition rewards security security research software development vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Recognizing Q4 Top 5 Bounty Hunters
We have tabulated the results from April-June 2018. The Top 5 Bounty Hunters for Q4 are now in. As with our list from Q3, we want to recognize both the leaders in payouts and in number of successful submissions. We appreciate the hard work and dedication of the following individuals and...- News
- Thread
- april ashar javed awards black hat bounty hunters bug bounty cameron vincent june marcin towalski microsoft msrc payouts qihoo 360 recognition research security security research submission top 5 vulcan team
- Replies: 0
- Forum: Security Alerts
-
Speculative Execution Bounty Launch
Today, Microsoft is announcing the launch of a limited-time bounty program for speculative execution side channel vulnerabilities. This new class of vulnerabilities was disclosed in January 2018 and represented a major advancement in the research in this field. In recognition of that threat...- News
- Thread
- attack techniques bounty program bounty tiers coordinated disclosure cve-2017-5715 cve-2017-5753 microsoft microsoft azure mitigation payouts research security research speculative execution threat landscape tier 1 tier 2 tier 3 tier 4 vulnerabilities windows 10
- Replies: 0
- Forum: Security Alerts
-
Inside the MSRC– The Monthly Security Update Releases
For the second in this series of blog entries we want to look into which vulnerability reports make it into the monthly release cadence. It may help to start with some history. In September 2003 we made a change from a release anytime approach to a mostly predictable, monthly release cadence...- News
- Thread
- automatic updates backporting customer action extended security updates fix documentation microsoft security monthly releases online services opportunistic updates phil misner risk assessment risk management security lifecycle security research software release support lifecycle update tuesday vulnerabilities vulnerability reporting
- Replies: 0
- Forum: Security Alerts
-
Inside the MSRC – How we recognize our researchers
This is the first of a series of blog entries to give some insight into the Microsoft Security Response Center (MSRC) business and how we work with security researchers and vulnerability reports. The Microsoft Security Response Center actively recognizes those security researchers who help us...- News
- Thread
- acknowledgement awards bug bounty community customer security cve engagement extended security updates insights microsoft monthly bulletin online services operational security research response center security security research submission threat landscape vulnerability
- Replies: 0
- Forum: Security Alerts
-
Coming together to address Encapsulated PostScript (EPS) attacks
Today’s security updates include three updates that exemplify how the security ecosystem can come together to help protect consumers and enterprises. We would like to thank FireEye and ESET for working with us. Customers that have the latest security updates installed are protected against the...- News
- Thread
- antivirus consumer protection cumulative update cve-2017-0261 cve-2017-0262 cve-2017-0263 elevation of privilege enterprise eps malware microsoft office phishing postscript security security research update vulnerability windows 10 word
- Replies: 0
- Forum: Security Alerts
-
Protecting customers and evaluating risk
Today, Microsoft triaged a large release of exploits made publicly available by Shadow Brokers. Understandingly, customers have expressed concerns around the risk this disclosure potentially creates. Our engineers have investigated the disclosed exploits, and most of the exploits are already...- News
- Thread
- collaboration customer safety cve-2017-0146 cve-2017-0147 engineering exchange 2010 exploit microsoft patch protection research response center risk assessment security security research threat mitigation update vulnerabilities windows 7
- Replies: 0
- Forum: Security Alerts
-
VIDEO Cracking Windows by Atom Bombing - Computerphile
:eek:- whoosh
- Thread
- computerphile cybersecurity education security research windows security
- Replies: 1
- Forum: The Water Cooler
-
Introducing Windows Defender Application Guard for Microsoft Edge
We’re determined to make Microsoft Edge the safest and most secure browser. Over the past two years, we have been continuously innovating, and we’re proud of the progress we’ve made. This is reflected by Microsoft Edge having the fewest vulnerabilities of any major browser on Windows since our...- News
- Thread
- application guard browser security corporate network cybersecurity data security defense in depth enterprise security hyper-v internet safety isolation technology malware microsoft edge organizational security security research targeted attacks user credentials virtualization web development windows defender
- Replies: 0
- Forum: Live RSS Feeds
-
Microsoft Bounty Programs Expansion – Microsoft Edge Remote Code Execution (RCE) Bounty
I’m very happy to announce another addition to the Link Removed. Microsoft will be hosting a bounty for Remote Code Execution vulnerabilities in Microsoft Edge on Windows Insider Preview builds. This bounty continues our partnership with the security research community in working to secure our...- News
- Thread
- bounty payouts bounty program chakra community microsoft microsoft edge open source osa penetration testing pre-release remote code execution research sdl security security research software development vulnerabilities windows features windows insider
- Replies: 0
- Forum: Security Alerts
-
Microsoft Bounty Programs Announce Expansion – Bounty for Microsoft OneDrive
At Microsoft, we continue to add new properties to our security bug bounty programs to help keep our customer’s secure. Today, I’m pleased to announce the addition of Microsoft OneDrive to the Microsoft Online Services Bug Bounty Program. This addition further incentivizes security researchers...- News
- Thread
- announcement bounty program bug bounty cansecwest customer security expansion incentives microsoft microsoft booth onedrive online services payouts programs research security security research submission tech news vancouver vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Microsoft Bounty Programs Expansion - Bounty for Defense, Authentication Bonus, and RemoteApp
I am very pleased to be releasing additional expansions of the Link Removed. Please stop by the Microsoft Networking Lounge at Black Hat, August 5-6, to learn more about these programs; or, visit Link Removed. We are raising the Bounty for Defense maximum from $50,000 USD to $100,000 USD. I am...- News
- Thread
- authentication azure active directory black hat bounty program bug bounty contest defense bounty feedback las vegas microsoft microsoft account networking lounge online services payouts penetration testing remoteapp research community sdl security research vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Introduction: Chris Betz, new head of MSRC
By way of introduction, I am Chris Betz, the leader of the Microsoft Security Response Center (MSRC). I’m stepping in to fill the shoes of Mike Reavey, who has moved on to become the General Manager of Secure Operations, still within Trustworthy Computing. Since joining the MSRC, I’ve spent...- News
- Thread
- bounty program chris betz customer issues cyber threats enterprise security global team it professionals microsoft microsoft security msrc professional dedication progress report response security security research tech evolution trustworthy computing update tuesday vulnerability
- Replies: 0
- Forum: Security Alerts
-
Introduction: Chris Betz, new head of MSRC
By way of introduction, I am Chris Betz, the leader of the Microsoft Security Response Center (MSRC). I’m stepping in to fill the shoes of Mike Reavey, who has moved on to become the General Manager of Secure Operations, still within Trustworthy Computing. Since joining the MSRC, I’ve spent...- News
- Thread
- bounty program chris betz consumer protection cyber threats dedication enterprise security global team information security it professionals microsoft msrc progress report response security security incident security research technology trustworthy computing update tuesday vulnerability
- Replies: 0
- Forum: Security Alerts
-
Announcing the BlueHat Prize for Advancement of Exploit Mitigations
Protecting the general computing ecosystem is a really tough job, and given some of the media headlines, it’s easy to get discouraged and wallow in the problems. It seems like we’re constantly bombarded with statistics measuring the number of bugs, vulnerabilities, or attacks in an...- News
- Thread
- active protections program bluehat prize collaboration computing ecosystem customers cybersecurity defense technology exploit prevention global security incentives industry collaboration innovation microsoft prizes research community security challenges security research security vendors threat landscape vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
December 2010 Advance Notification Service is released
Hi everyone. Mike Reavey from the MSRC here. Today we're releasing our Link Removed due to 404 Error for the December 2010 security bulletin release. As we do every month, we've given information about the coming December release and provided links to detailed information so you can plan your...- News
- Thread
- 2011 aslr critical update customer feedback dep end of support important updates internet explorer lifecycle microsoft msrc patch management release notifications security bulletin security research stuxnet update vulnerabilities vulnerability reporting webcast
- Replies: 0
- Forum: Security Alerts