-
BlueHat Prize: And the finalists are...
Hello, The judges have finished reviewing the submissions for the first BlueHat Prize contest and the finalists are in! Please visit Link Removed due to 404 Error for details on the three finalists and their entries that mitigate return-oriented programming (ROP). The finalists will collectively...- News
- Thread
- black hat bluehat prize finalists las vegas microsoft prizes rop security submission trustworthy computing
- Replies: 0
- Forum: Security Alerts
-
Further insight into Security Advisory 2719615
During our regular Update Tuesday bulletin cycle this week, we released Security Advisory 2719615, which provides guidance concerning a remote code execution issue affecting MSXML Code Services. As part of that Advisory, we've built a Fix it workaround that blocks the potential attack vector in...- News
- Thread
- advisory fix guidance internet explorer msxml remote code execution security trustworthy computing update vulnerability
- Replies: 0
- Forum: Security Alerts
-
Advance Notification Service for June 2012 Security Bulletin Release
Hello -- Today we’re releasing our advance notification for the June security bulletin release, which is scheduled for Tuesday, June 12. This month’s release includes 7 bulletins addressing 28 vulnerabilities in Microsoft Windows, Internet Explorer, Visual Basic for Applications...- News
- Thread
- advance notification angela gunn bulletin deployment dustin childs dynamics ax guidance internet explorer june microsoft net framework risk security testing trustworthy computing update visual basic vulnerabilities webcast windows
- Replies: 0
- Forum: Security Alerts
-
Security Advisory 2718704: Collision attack details, WU update rollout
Today, as a part of our continuing phased mitigation strategy recently discussed, we have initiated the additional hardening of Windows Update. We’ve also provided more information about the MD5 hash-collision attacks used by the Flame malware in the SRD blog. This information should help...- News
- Thread
- advisory attack automatic updates certificate code signing collision cryptography customer service hardening information integrity malware md5 mitigation phased strategy protection security trustworthy computing windows update windows vista
- Replies: 0
- Forum: Security Alerts
-
Microsoft releases Security Advisory 2718704
Hello, We recently became aware of a complex piece of targeted malware known as “Flame” and immediately began examining the issue. As many reports assert, Flame has been used in highly sophisticated and targeted attacks and, as a result, the vast majority of customers are not at...- News
- Thread
- advisory antivirus certification cryptography cybersecurity enterprise flame licensing malware microsoft remote desktop risk mitigation security targeted attacks trustworthy computing update vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
May 2012 Security Bulletin Webcast, Slide Deck, and Q&A
Hello, Today we published the Link Removed due to 404 Error, and the Link Removed due to 404 Error. During the webcast, we fielded 8 questions on various topics, including bulletins released, deployment tools, and update detection tools. We invite our customers to join us for the next public...- News
- Thread
- bulletin customer service deployment june live microsoft pdt questions security tools trustworthy computing update utc webcast
- Replies: 0
- Forum: Security Alerts
-
Windows XP and Office 2003 countdown to end of support, and the April 2012 bulletins
Hello, As you know, today is Update Tuesday. Before I go into the bulletin details, however, I wanted to let you know that today we’re notifying customers that Windows XP and Office 2003 will go out of support in April 2014. We understand that preparing to deploy the latest versions of...- News
- Thread
- april 2012 automatic updates bulletin release critical update cve deployment end of support internet explorer malware microsoft office 2003 organizational upgrade remote code execution security bulletin security updates trustworthy computing update tuesday user rights webcast windows xp
- Replies: 0
- Forum: Security Alerts
-
BlueHat Prize: And now the fun begins
The entry window for the first annual BlueHat Prize closed at 11:59pm PDT on April 1. We've been eagerly awaiting a final entry count from the contest organizers, and senior security strategist Katie Moussouris has just posted that tally on the EcoStrat blog. Congratulations to all participants...- News
- Thread
- blog bluehat prize contest ecostrat judging process katie moussouris offensive security participants security trustworthy computing
- Replies: 0
- Forum: Security Alerts
-
Countdown to Defensive Security Innovations Competition: Final Submission Days!
Nearly nine months after we announced the first annual Link Removed due to 404 Error competition for innovations in defensive security technologies, we’re just days away from the submission deadline. On the EcoStrat blog today, Senior Security Strategist Katie Moussouris gives a glimpse...- News
- Thread
- competition deadline ecostrat innovation katie moussouris mad loot offensive security security technology submission trustworthy computing
- Replies: 0
- Forum: Security Alerts
-
Proof-of-Concept Code available for MS12-020
On March 15, we became aware of public proof-of-concept code that results in denial of service for the issue addressed by MS12-020, which we released Tuesday. We continue to watch the threat landscape and we are not aware of public proof-of-concept code that results in remote code execution...- News
- Thread
- active protections program confidentiality consumer protection cve-2012-0002 denial of service deployment extended security updates mapp microsoft mitigation ms12-020 optimal decisions proof of concept remote code execution security software vendors threat landscape trustworthy computing update vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
March 2012 ANS
Hello. Today we’re releasing our advance notification for the March security bulletin release, which is scheduled for Tuesday, March 13. This month’s release includes six bulletins addressing seven vulnerabilities in Microsoft Windows, Visual Studio, and Expression Design. As always...- News
- Thread
- bulletin customer advisory deployment dustin childs expression design impact analysis march microsoft overview pete voss risk assessment security testing trustworthy computing update visual studio vulnerabilities webcast windows
- Replies: 0
- Forum: Security Alerts
-
MSRC looks back at ten years, and the February 2012 bulletins
Ever wondered where Update Tuesday bulletins come from, or what it’s like around Microsoft when a serious information-security situation arises? Or wondered who precisely is responsible for getting your monthly bulletin releases out the door? Update Tuesday, which brings us here today, is...- News
- Thread
- 2012 bulletin c runtime collaboration cumulative update deployment ecosystem exploitability incident response internet explorer microsoft msrc remote code execution research security technet trustworthy computing update vulnerabilities webcast
- Replies: 0
- Forum: Security Alerts
-
ANS for February 2012, and some notes on SDL
Hello. Today we’re releasing our advance notification for the February security bulletin release, which is scheduled for Tuesday, February 14. This month’s release includes nine bulletins addressing 21 vulnerabilities in Microsoft Windows, Office, Internet Explorer, and...- News
- Thread
- bulletin conference deployment engineering february guidance internet explorer microsoft office sdl security testing trustworthy computing vulnerabilities webcast windows
- Replies: 0
- Forum: Security Alerts
-
January 2012 Security Bulletins Released
Hello. As I previously mentioned in the Advance Notification Service blog post on Thursday, today we are releasing seven security bulletins, one of which is rated Critical in severity, with the remaining six classified as Important. These bulletins will address eight vulnerabilities in Microsoft...- News
- Thread
- bulletin compatibility critical update customer guidance deployment exploitability knowledge base media player microsoft ms12-004 patch management remote code execution risk assessment security security advisory ssl trustworthy computing update vulnerabilities webcast
- Replies: 0
- Forum: Security Alerts
-
January 2012 ANS is released
Hello. Today we’re releasing our advance notification for the January security bulletin release, which is scheduled for Tuesday, January 10. This month’s release includes seven bulletins addressing eight vulnerabilities in Microsoft Windows and Microsoft Developer Tools And Software...- News
- Thread
- advance notification ans release deployment dustin childs exploit impact analysis january 2012 live questions microsoft pete voss pst risk assessment security bulletin security features sfb classification testing trustworthy computing vulnerabilities webcast
- Replies: 0
- Forum: Security Alerts
-
December 2011 Out-Of-Band Bulletin Release: Q&A and Webcast
Hello, Today we published the December 2011 Out-of-Band Security Bulletin Webcast Questions & Answers page. We fielded 41 questions on the subject of MS11-100 . There were four questions during the webcast that we were unable to answer and we have included those questions and answers on the...- News
- Thread
- 2011 bulletin customer engagement january 2012 live event microsoft ms11-100 pst q&a questions response security trustworthy computing update webcast
- Replies: 0
- Forum: Security Alerts
-
Advanced Notification for out-of-band release to address Security Advisory 2659883
Hello, Today we’re providing advance notification for an out-of-band security update to address the publicly disclosed issue described in Security Advisory 2659883. The release is scheduled for tomorrow, December 29, at approximately 10 a.m. PST. The bulletin has a severity rating of...- News
- Thread
- advisory asp.net critical microsoft out-of-band security trustworthy computing update vulnerability webcast
- Replies: 0
- Forum: Security Alerts
-
News from MAPP, and Advance Notification Service for the December 2011 Bulletin Release
Hello all. Before we look at next week’s bulletin release, we’d like to point out an update to our Microsoft Active Protections Program (MAPP) that should provide customers with greater transparency as to how MAPP partners use the information we share with them when we release...- News
- Thread
- advisory bulletin december deployment insights internet explorer live questions mapp microsoft notifications office protection security testing transparency trustworthy computing update vulnerabilities webcast windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft hosts BlueHatv11, releases four bulletins
Hello, On this November Update Tuesday, we’re recapping the Link Removed, which Microsoft hosted in Redmond last week. We are also releasing four security updates, so please read on for details. Microsoft hosted its Link Removed of the BlueHat conference Nov. 2-4. The event featured...- News
- Thread
- bluehat bulletin cve deployment exploitability installation microsoft november protection remote code execution research research community security tcp/ip trustworthy computing update vulnerability webcast
- Replies: 0
- Forum: Security Alerts
-
October Update Tuesday: Security Intelligence Report volume 11 announced
Hello, On this October Update Tuesday, we are releasing the 11th volume of the Security Intelligence Report, Link Removed which puts zero-day vulnerabilities into context against other global threats. We are also releasing eight security updates so please read on for details. A new method of...- News
- Thread
- .net automatic updates critical update cve deployment important updates internet explorer malware october update remote code execution security bulletin security report security updates silverlight tech discussion trustworthy computing vulnerabilities webcast
- Replies: 0
- Forum: Security Alerts