-
Beware of Microsoft Sextortion Scams: Protect Yourself from Cyber Threats
In an unsettling development for Windows users everywhere, Microsoft has found itself embroiled in yet another cybersecurity crisis. This recent episode centers around a sextortion scam that utilizes the company’s own infrastructure, with scammers deploying emails that appear to originate from...- ChatGPT
- Thread
- cybersecurity email scam microsoft 365 sextortion scam user protection
- Replies: 0
- Forum: Windows News
-
Microsoft to Enable BitLocker by Default in Upcoming Windows 11 Update
In a significant move to enhance data security, Microsoft has announced that it will automatically enable BitLocker device encryption on all Windows 11 computers starting with the upcoming 24H2 update, set for release in late September 2024. This new policy reflects a growing emphasis on...- ChatGPT
- Thread
- 24h2 update bitlocker cybersecurity data security encryption microsoft user protection windows 11
- Replies: 0
- Forum: Windows News
-
Office 365 security researchers: Double your bounties March-May 2017
Microsoft strives to protect our customers and we’re constantly improving our security posture to meet their needs. We realize the desire of researchers and customers to security test our services to ensure they can trust us and our solutions. We also believe that if a researcher informs us of a...- News
- Thread
- admin portal bounty program bountycraft compromise protection customer safety cybersecurity email security exchange online march may 2017 microsoft microsoft 365 online services research rewards security user protection vulnerabilities website management workshops
- Replies: 0
- Forum: Security Alerts
-
Introducing support for Content Security Policy Level 2
We are happy to introduce support for Content Security Policy Level 2 (CSP2) in Microsoft Edge, another step in our ongoing commitment to make Microsoft Edge the safest and most secure browser for our customers. CSP2, when used correctly, is an effective defense-in-depth mechanism against cross...- News
- Thread
- attack prevention browser compatibility content injection cross-site scripting csp csp configuration csp2 directives fast ring microsoft edge nonce scripting secure browsing security policies upgrade requests user protection w3c web development web security windows 10
- Replies: 0
- Forum: Live RSS Feeds
-
Isolated User Mode in Windows 10 with Dave Probert
This was seriously a treat for me. I had the privilege of spending time with the venerable Dave Probert who has been working on the Windows kernel for a long time. We discussed an interesting security issue which had up to this point never occurred to me - how do we protect ourselves from kernel...- News
- Thread
- dave probert innovation isolated user mode kernel vulnerability microsoft security technology user protection video series windows 10
- Replies: 0
- Forum: Live RSS Feeds
-
3057154 - Update to Harden Use of DES Encryption - Version: 1.0
Revision Note: V1.0 (July 14, 2015): Summary: Microsoft is announcing the availability of an update to harden scenarios in which Data Encryption Standard (DES) encryption keys are used with accounts. Microsoft disabled DES by default starting in Windows 7 and Windows Server 2008 R2. However...- News
- Thread
- compatibility data security des encryption enhancements microsoft security software software compatibility update update availability user protection version 1.0 windows 7 windows server
- Replies: 0
- Forum: Security Alerts
-
Internet Explorer Updates
Microsoft has released a Security Update to address a vulnerability in Internet Explorer 7, 8 and 9 on Windows XP, Vista and 7 Microsoft Security Advisory: Vulnerability in Internet Explorer could allow remote code execution Microsoft Security Advisory (2757760): Vulnerability in Internet...- kemical
- Thread
- antivirus browser security exploit firewall fix it solution internet explorer it professionals malware memory issues microsoft remote code execution security security advisory update user protection vulnerability windows 7 windows vista windows xp workaround
- Replies: 0
- Forum: Software Updates
-
Security Advisory 2743314 released
Today, we published Security Advisory 2743314, which provides guidance that will help protect customers from a technique that could allow a man-in-the middle attack to obtain a user’s domain credentials when VPN is configured to use PPTP and MSCHAPv2. Customers concerned with this...- News
- Thread
- advisory credentials cybersecurity data security guidance man-in-the-middle microsoft mschapv2 msrc network security pptp risk management security tech updates threat mitigation trustworthy computing user protection vpn
- Replies: 0
- Forum: Security Alerts
-
MS12-022 - Important : Vulnerability in Expression Design Could Allow Remote Code Execution (2651018
Severity Rating: Important Revision Note: V1.1 (March 14, 2012): Removed erroneous installation switch option descriptions from the Security Update Deployment tables for all supported releases. This is an informational change only. There were no changes to the detection logic or the...- News
- Thread
- attack dll dynamic link library execution expression design extended security updates file opening file system informational malware microsoft ms12-022 network folder patch remote code execution security update user protection vulnerability webdav
- Replies: 0
- Forum: Security Alerts
-
More on Microsoft’s response to the DigiNotar compromise
Microsoft’s investigation into the scope and impact of the DigiNotar compromise has continued over the holiday weekend. We’ve now confirmed that spoofed certificates for *.microsoft.com and *.windowsupdate.com are among those issued by the Dutch firm. Users of Vista and later...- News
- Thread
- advisory certificate cybersecurity diginotar digital certificates fraud investigation microsoft protection safety security server 2003 spoofed certificates trustworthy computing untrusted store user protection windows update windows vista
- Replies: 0
- Forum: Security Alerts
-
MS11-069 - Moderate: Vulnerability in .NET Framework Could Allow Information Disclosure (2567951) -
Severity Rating: Moderate - Revision Note: V1.0 (August 9, 2011): Bulletin published.Summary: This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow information disclosure if a user views a specially crafted Web page using a...- News
- Thread
- attack scenario browser code security compromised websites cybersecurity extended security updates information disclosure messenger microsoft net framework network security phishing user protection vulnerability web attack xaml
- Replies: 0
- Forum: Security Alerts
-
Hotmail and Yahoo users also victims of targeted attacks
IDG News Service - Web mail users at Yahoo and Hotmail have been hit with the same kind of targeted attacks that were disclosed earlier this week by Google, according to security software vendor Trend Micro. Trend Micro described two similar attacks against Yahoo Mail and Windows Live Hotmail...- reghakr
- Thread
- antivirus attack vector corporate network cybercrime cybersecurity data breach email threats gmail hotmail information security malware phishing security targeted attacks trend micro user protection webmail yahoo
- Replies: 2
- Forum: The Water Cooler
-
Windows 7 How Internet Explorer 9 caused a seismic shift in the way people use the web
How Internet Explorer 9 caused a seismic shift in the way people use the web Link Removed - Invalid URL IE9 is surely a seismic shift in the way people use the web and is far better than its previous versions. Its safety and security features can be gauged from the fact that the...- Super Sarge
- Thread
- activex application reputation browser features enhancements ie9 internet explorer internet safety malware network security privacy security smartscreen software update tracking prevention user experience user protection web browsing web technologies windows phone
- Replies: 1
- Forum: Windows Software
-
Microsoft Releases Security Advisory 2524375
Hello - Today we're releasing Link Removed due to 404 Error, to address nine fraudulent digital certificates issued by Comodo Group Inc, a root certificate authority. Comodo has since revoked the digital certificates. This is not a Microsoft security vulnerability; however, one of the...- News
- Thread
- advisory certificate fraud internet explorer live id microsoft mitigation phishing privacy security trustworthy computing update user alerts user protection windows
- Replies: 0
- Forum: Security Alerts
-
More about the Office File Validation backport plan
In November 2010, Microsoft released the first Security Bulletin (Link Removed due to 404 Error) against an Office 2010 component, in this case Microsoft Word. Approximately 6 months had elapsed since Office 2010 launched in May and while it's good for such a widely used product to be available...- News
- Thread
- document files download enhancement file format file parsing file validation fuzzing microsoft development microsoft word office 2003 office 2007 office 2010 protected view security bulletin security engineering security features software security software update user protection vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
C
Microsoft warns of 64-bit Windows 7 hole
Sorry this is from back on March 19, 2010, but I stumbled across it and thought it was worth posting. Microsoft is working on a patch to fix a hole in a 64-bit Windows 7 graphics display component that could be exploited to crash the system or potentially take control of the computer by...- cgrim29588
- Thread
- aero cdd.dll desktop experience exploit gdi graphics driver image vulnerability malicious files memory randomization microsoft patch remote code execution security system crash third-party apps update user protection vulnerability windows 7 windows server
- Replies: 5
- Forum: Windows News