By way of introduction, I am Chris Betz, the leader of the Microsoft Security Response Center (MSRC). I’m stepping in to fill the shoes of Mike Reavey, who has moved on to become the General Manager of Secure Operations, still within Trustworthy Computing.
Since joining the MSRC, I’ve spent...
bounty program
chris betz
customer issues
cyber threats
enterprise security
global team
it professionals
microsoft
microsoft security
msrc
professional dedication
progress report
response
security
security research
tech evolution
trustworthycomputing
update tuesday
vulnerability
As the proliferation of devices continues to capture the imagination of consumers, and has ignited what is referred to as bring your own device (BYOD) revolution, many IT departments across the globe are now facing increased security considerations. While organizations encourage BYOD for cost...
activesync
attack
authentication
byod
certificate
cost savings
cybersecurity
device management
encryption
exchange
it department
malware
policy
productivity
security
security features
third party
trustworthycomputing
user education
windows phone
Today we’re publishing the Link Removed. The majority of questions focused on the ActiveX Kill Bits bulletin (MS13-090) and the advisories. We also answered a few general questions that were not specific to any of this month’s updates, but that may be of interest.
We’ve discussed the Microsoft...
activex
analyzer
bulletin
december
deployment
feedback
mbsa
microsoft
public preview
q&a
release
security
server
slide deck
support
technet
trustworthycomputing
update
webcast
windows
By way of introduction, I am Chris Betz, the leader of the Microsoft Security Response Center (MSRC). I’m stepping in to fill the shoes of Mike Reavey, who has moved on to become the General Manager of Secure Operations, still within Trustworthy Computing.
Since joining the MSRC, I’ve spent...
bounty program
chris betz
consumer protection
cyber threats
dedication
enterprise security
global team
information security
it professionals
microsoft
msrc
progress report
response
security
security incident
security research
technology
trustworthycomputing
update tuesday
vulnerability
This month we release eight bulletins – four Critical and four Important - which address 26 unique CVEs in Microsoft Windows, Internet Explorer, SharePoint, .NET Framework, Office, and Silverlight. For those who need to prioritize their deployment planning, we recommend focusing on MS13-080...
advisory
bulletin
cve
deployment
exploitability
internet explorer
md5
microsoft
net framework
october
office
remote code execution
security
sharepoint
ssl
trustworthycomputing
update
vulnerabilities
webcast
windows
Over the years, we've put a lot of work into helping secure the computing ecosystem and limiting the number of issues in our products. The security researcher community is critical to these efforts, as they help us find vulnerabilities in our software that we may have missed.
Now we're taking...
It was just over one year ago, May 28, 2012, to be exact, that I transitioned from running active MSRC cases and writing bulletins to my current role managing software security incidents. A lot has changed in that year - and I’ve dealt with some interesting issues during my tenure - but...
certificate
consumer protection
cryptography
cumulative update
deployment priority
digital certificates
internet explorer
june 2013
microsoft office
pki
remote code execution
security
security advisories
software security
trustworthycomputing
update management
vulnerabilities
windows 7
windows update
windows vista
For those who couldn’t attend the live webcast, today we’re publishing the Link Removed. We fielded 13 questions on various topics during the webcast, with specific bulletin questions focusing primarily on Internet Explorer (MS13-037 and MS13-038) and Visio (MS13-044).
We invite...
Today, we are releasing 10 bulletins, addressing 33 vulnerabilities in Microsoft products. Before we get into the details, we wanted to first let our enterprise customers know about a change in how we’re communicating technical details within our security advisories. Starting today...
advisories
bulletin
consumer protection
cumulative
denial of service
deployment
emergency patch
exploitability
internet explorer
knowledge base
microsoft
msrc
risk management
security
tech support
trustworthycomputing
update
vulnerabilities
webcast
windows
Today we’re providing Advance Notification of 10 bulletins for release on Tuesday, May 14, 2013. This release brings two Critical and eight Important-class bulletins, which address 34 unique vulnerabilities. The Critical-rated bulletins address issues in Microsoft Windows and Internet...
2013
analysis
bulletin
critical
deployment
guidance
important
internet explorer
microsoft
net framework
office
pst
risk
security
server
testing
trustworthycomputing
update
vulnerabilities
windows
In celebration of spring’s onset, today we’re providing advance notification for the April 2013 release of nine bulletins; two Critical and seven Important. The Critical bulletins address vulnerabilities in Microsoft Windows and Internet Explorer, and the seven Important-rated...
antimalware
april 2012
bulletin
critical
deployment
impact analysis
important
internet explorer
microsoft
msrc
notifications
office
risk assessment
security
server software
testing
trustworthycomputing
update
vulnerabilities
windows
As my career in security response has grown over the years, I am often reminded of the words of Italian author Giuseppe Tomasi Di Lampedusa, who stated, “If we want everything to remain as it is, it will be necessary for everything to change.” There are some things that we wish to...
advisory
bulletin
deployment
exploitation
guidance
internet explorer
kernel drivers
march 2013
microsoft
microsoft store
physical access
privacy
protection
remote code execution
security
silverlight
threats
trustworthycomputing
update
vulnerabilities
Today we’re providing advance notification for the release of seven bulletins, four Critical and three Important, for March 2013. The Critical bulletins address vulnerabilities in Microsoft Silverlight, Internet Explorer, Office and Microsoft Server Software. The three Important-rated...
bulletin
critical
deployment
important
internet explorer
march 2013
microsoft
notifications
office
risk assessment
security
server software
silverlight
technet
testing
trustworthycomputing
update
vulnerabilities
windows
As reported by Facebook and Link Removed, Microsoft can confirm that we also recently experienced a similar security intrusion.
Consistent with our security response practices, we chose not to make a statement during the initial information gathering process. During our investigation, we found...
Before we discuss this month’s release, I wanted to briefly touch on the big event happening this week. No, I’m not talking about the romantically-themed holiday on Thursday. I’m talking about the start of spring training and the return of baseball. There are a few things I am...
address space layout randomization
baseball
bulletin
configuration
data execution prevention
deployment
exploit
february 2013
guidance
internet explorer
microsoft
mitigation
protection
remote code execution
security
toolkit
trustworthycomputing
update
vulnerabilities
webcast
We’re kicking off the February 2013 Security Bulletin Release with Advance Notification of 12 bulletins for release Tuesday, February 12. This release brings five Critical and seven Important-class bulletins, which address 57 unique vulnerabilities. The Critical-rated bulletins address...
bulletin
communication
critical issues
deployment
exchange
february
important issues
internet explorer
microsoft
msrc
net framework
notifications
office
risk assessment
security
server software
trustworthycomputing
update
vulnerabilities
windows
Today we’re publishing the Link Removed. During the webcast, we fielded 17 questions focusing on Security Update MS13-088, and SecurityAdvisory 2794220 which was deprecated by this update release. All questions and answers are included in the transcript.
We invite our customers to join...
Today, we are providing Advance Notification to customers that at approximately 10 a.m. PST on Monday, January 14, 2013, we will release an out-of-band security update to fully address the issue described in Security Advisory 2794220. While we have still seen only a limited number of customers...
Today we’re publishing the Link Removed. During the webcast, we fielded 12 questions focusing primarily on the Print Spooler (Link Removed) and .NET Framework (Link Removed) updates. All questions are included on the Q&A page.
We invite our customers to join us for the next scheduled...
bulletin
community
customers
event
february
knowledge
live
microsoft
net framework
print spooler
pst
q&a
registration
security
trustworthycomputing
update
utc
webcast
webinar
At the end of each year, some folks take a moment to jot down predictions about what the coming year has in store. I, on the other hand, do not do predictions. I am neither prognosticator, seer, fortune teller, prophet, clairvoyant, soothsayer, nor medium; although I have been accused of being a...