Hello,
The judges have finished reviewing the submissions for the first BlueHat Prize contest and the finalists are in! Please visit Link Removed due to 404 Error for details on the three finalists and their entries that mitigate return-oriented programming (ROP). The finalists will collectively...
During our regular Update Tuesday bulletin cycle this week, we released Security Advisory 2719615, which provides guidance concerning a remote code execution issue affecting MSXML Code Services. As part of that Advisory, we've built a Fix it workaround that blocks the potential attack vector in...
Hello --
Today we’re releasing our advance notification for the June security bulletin release, which is scheduled for Tuesday, June 12. This month’s release includes 7 bulletins addressing 28 vulnerabilities in Microsoft Windows, Internet Explorer, Visual Basic for Applications...
advance notification
angela gunn
bulletin
deployment
dustin childs
dynamics ax
guidance
internet explorer
june
microsoft
net framework
risk
security
testing
trustworthycomputing
update
visual basic
vulnerabilities
webcast
windows
Today, as a part of our continuing phased mitigation strategy recently discussed, we have initiated the additional hardening of Windows Update. We’ve also provided more information about the MD5 hash-collision attacks used by the Flame malware in the SRD blog. This information should help...
Hello,
We recently became aware of a complex piece of targeted malware known as “Flame” and immediately began examining the issue. As many reports assert, Flame has been used in highly sophisticated and targeted attacks and, as a result, the vast majority of customers are not at...
Hello,
Today we published the Link Removed due to 404 Error, and the Link Removed due to 404 Error. During the webcast, we fielded 8 questions on various topics, including bulletins released, deployment tools, and update detection tools.
We invite our customers to join us for the next public...
Hello,
As you know, today is Update Tuesday. Before I go into the bulletin details, however, I wanted to let you know that today we’re notifying customers that Windows XP and Office 2003 will go out of support in April 2014. We understand that preparing to deploy the latest versions of...
april 2012
automatic updates
bulletin release
critical update
cve
deployment
end of support
internet explorer
malware
microsoft
office 2003
organizational upgrade
remote code execution
security bulletin
security updates
trustworthycomputing
update tuesday
user rights
webcast
windows xp
The entry window for the first annual BlueHat Prize closed at 11:59pm PDT on April 1. We've been eagerly awaiting a final entry count from the contest organizers, and senior security strategist Katie Moussouris has just posted that tally on the EcoStrat blog. Congratulations to all participants...
Nearly nine months after we announced the first annual Link Removed due to 404 Error competition for innovations in defensive security technologies, we’re just days away from the submission deadline. On the EcoStrat blog today, Senior Security Strategist Katie Moussouris gives a glimpse...
On March 15, we became aware of public proof-of-concept code that results in denial of service for the issue addressed by MS12-020, which we released Tuesday.
We continue to watch the threat landscape and we are not aware of public proof-of-concept code that results in remote code execution...
Hello. Today we’re releasing our advance notification for the March security bulletin release, which is scheduled for Tuesday, March 13. This month’s release includes six bulletins addressing seven vulnerabilities in Microsoft Windows, Visual Studio, and Expression Design. As always...
Ever wondered where Update Tuesday bulletins come from, or what it’s like around Microsoft when a serious information-security situation arises? Or wondered who precisely is responsible for getting your monthly bulletin releases out the door?
Update Tuesday, which brings us here today, is...
Hello. Today we’re releasing our advance notification for the February security bulletin release, which is scheduled for Tuesday, February 14. This month’s release includes nine bulletins addressing 21 vulnerabilities in Microsoft Windows, Office, Internet Explorer, and...
bulletin
conference
deployment
engineering
february
guidance
internet explorer
microsoft
office
sdl
security
testing
trustworthycomputing
vulnerabilities
webcast
windows
Hello. As I previously mentioned in the Advance Notification Service blog post on Thursday, today we are releasing seven security bulletins, one of which is rated Critical in severity, with the remaining six classified as Important.
These bulletins will address eight vulnerabilities in Microsoft...
Hello. Today we’re releasing our advance notification for the January security bulletin release, which is scheduled for Tuesday, January 10. This month’s release includes seven bulletins addressing eight vulnerabilities in Microsoft Windows and Microsoft Developer Tools And Software...
advance notification
ans release
deployment
dustin childs
exploit
impact analysis
january 2012
live questions
microsoft
pete voss
pst
risk assessment
security bulletin
security features
sfb classification
testing
trustworthycomputing
vulnerabilities
webcast
Hello,
Today we published the December 2011 Out-of-Band Security Bulletin Webcast Questions & Answers page. We fielded 41 questions on the subject of MS11-100 . There were four questions during the webcast that we were unable to answer and we have included those questions and answers on the...
Hello,
Today we’re providing advance notification for an out-of-band security update to address the publicly disclosed issue described in Security Advisory 2659883. The release is scheduled for tomorrow, December 29, at approximately 10 a.m. PST.
The bulletin has a severity rating of...
Hello all. Before we look at next week’s bulletin release, we’d like to point out an update to our Microsoft Active Protections Program (MAPP) that should provide customers with greater transparency as to how MAPP partners use the information we share with them when we release...
advisory
bulletin
december
deployment
insights
internet explorer
live questions
mapp
microsoft
notifications
office
protection
security
testing
transparency
trustworthycomputing
update
vulnerabilities
webcast
windows
Hello,
On this November Update Tuesday, we’re recapping the Link Removed, which Microsoft hosted in Redmond last week. We are also releasing four security updates, so please read on for details.
Microsoft hosted its Link Removed of the BlueHat conference Nov. 2-4. The event featured...
bluehat
bulletin
cve
deployment
exploitability
installation
microsoft
november
protection
remote code execution
research
research community
security
tcp/ip
trustworthycomputing
update
vulnerability
webcast
Hello,
On this October Update Tuesday, we are releasing the 11th volume of the Security Intelligence Report, Link Removed which puts zero-day vulnerabilities into context against other global threats. We are also releasing eight security updates so please read on for details.
A new method of...