Security Research & Defense

Subscribe to Security Research & Defense feed Security Research & Defense
Updated: 8 hours 8 min ago

Designing a COM library for Rust

Tue, 10/08/2019 - 13:00

I interned with Microsoft as a Software Engineering Intern in the MSRC UK team in Cheltenham this past summer. I worked in the Safe Systems Programming Language (SSPL) group, which explores safe programming languages as a proactive measure against memory-safety related vulnerabilities. This blog post describes the project that I have been working on under …

Designing a COM library for Rust Read More »

The post Designing a COM library for Rust appeared first on Microsoft Security Response Center.

Categories: Security News

October 2019 security updates are available!

Tue, 10/08/2019 - 12:58

We have released the October security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month’s security updates can be found in the Security Update Guide. As a reminder, Windows 7 and Windows Server 2008 R2 will be out of …

October 2019 security updates are available! Read More »

The post October 2019 security updates are available! appeared first on Microsoft Security Response Center.

Categories: Security News

[AD管理者向け] 2020 年 LDAP 署名と LDAP チャネルバインディングが有効化。確認を!

Wed, 10/02/2019 - 19:59

マイクロソフトでは、2020 年初頭に、Active Directory ドメイン環境内の LDAP 通信の安全性を向上するために、LDAP 署名、およびLDAP チャネルバインディング (LDAPS 利用時)を既定で有効化します。

The post [AD管理者向け] 2020 年 LDAP 署名と LDAP チャネルバインディングが有効化。確認を! appeared first on Microsoft Security Response Center.

Categories: Security News

Building the Azure IoT Edge Security Daemon in Rust

Mon, 09/30/2019 - 12:45

Azure IoT Edge is an open source, cross platform software project from the Azure IoT team at Microsoft that seeks to solve the problem of managing distribution of compute to the edge of your on-premise network from the cloud. This post explains some of the rationale behind our choice of Rust as the implementation programming …

Building the Azure IoT Edge Security Daemon in Rust Read More »

The post Building the Azure IoT Edge Security Daemon in Rust appeared first on Microsoft Security Response Center.

Categories: Security News

MSRC is going to ROOTCON!

Mon, 09/23/2019 - 14:48

The Microsoft Security Response Center (MSRC) works with partners all over the world to protect Microsoft customers. This week we’re headed to the Philippines to meet security researchers and bounty hunters at ROOTCON 13! Planning on attending ROOTCON? If you want to learn more about how you can earn rewards for reporting vulnerabilities to Microsoft …

MSRC is going to ROOTCON! Read More »

The post MSRC is going to ROOTCON! appeared first on Microsoft Security Response Center.

Categories: Security News

Meet the BlueHat Content Advisory Board

Wed, 09/18/2019 - 18:54

We couldn’t do BlueHat without the Content Advisory Board, the brain trust reviewing submissions to the CFP. Representing both Microsoft and other parts of security community, the CAB applies their industry and speaker experience to create the BlueHat agenda that’s the right mix of topics and perspectives. We really appreciate the time these people take …

Meet the BlueHat Content Advisory Board Read More »

The post Meet the BlueHat Content Advisory Board appeared first on Microsoft Security Response Center.

Categories: Security News

Calling all breakers & builders: BlueHat Seattle registration is open!

Mon, 09/16/2019 - 17:00

Exciting changes are coming to BlueHat Seattle 2019! If you’d like to attend this premier security conference, we have good news for you: registration for BlueHat Seattle is now open and we hope you register.   Wait, isn’t BlueHat invitation-only? It is…but if we haven’t sent you an invitation, we encourage you to request a seat. Visit our registration site and tell us a little bit about yourself. We’re reviewing all application requests and will send a confirmation if you are selected.   The BlueHat conference team is creating an engaging two-day agenda to provide a …

Calling all breakers & builders: BlueHat Seattle registration is open! Read More »

The post Calling all breakers & builders: BlueHat Seattle registration is open! appeared first on Microsoft Security Response Center.

Categories: Security News

Attacking the VM Worker Process

Wed, 09/11/2019 - 14:50

In the past year we invested a lot of time making Hyper-V research more accessible to everyone. Our first blog post, “First Steps in Hyper-V Research”, describes the tools and setup for debugging the hypervisor and examines the interesting attack surfaces of the virtualization stack components. We then published “Fuzzing para-virtualized devices in Hyper-V”, which …

Attacking the VM Worker Process Read More »

The post Attacking the VM Worker Process appeared first on Microsoft Security Response Center.

Categories: Security News

2019 年 9 月のセキュリティ更新プログラム (月例)

Tue, 09/10/2019 - 19:34

2019 年 9 月 11 日 (日本時間)、マイクロソフトは以下のソフトウェアのセキュリティ更新プログラムを公開しました。

The post 2019 年 9 月のセキュリティ更新プログラム (月例) appeared first on Microsoft Security Response Center.

Categories: Security News

September 2019 Security Updates

Tue, 09/10/2019 - 12:57

We have released the September security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month’s security updates can be found in the Security Update Guide. As a reminder, Windows 7 and Windows Server 2008 R2 will be out of …

September 2019 Security Updates Read More »

The post September 2019 Security Updates appeared first on Microsoft Security Response Center.

Categories: Security News

BlueHat Seattle 2019 Call for Papers is Now Open!

Tue, 09/03/2019 - 19:01
2019 has seen a phenomenal BlueHatIL in February followed by a wildly successful BlueHat Shanghai in May… now it’s time to come back home for BlueHat Seattle!  2 days of hands-on technical training (October 22-23, 2019)  2 days of conference talks from industry-leading security researchers and cyber defenders (October 24-25, 2019)  great creative spaces ready …

BlueHat Seattle 2019 Call for Papers is Now Open! Read More »

Categories: Security News

Acquiring a VHD to Investigate

Tue, 09/03/2019 - 15:30
In a previous post we described some of the differences between on-premises/physical forensics and cyber investigations and those performed in the cloud, and how this can make cloud forensics challenging. That blog post described a method of creating and maintaining a VM image which can be distributed to multiple regions, allowing you to deploy this …

Acquiring a VHD to Investigate Read More »

Categories: Security News

Scalable infrastructure for investigations and incident response

Fri, 08/30/2019 - 11:45
Traditional computer forensics and cyber investigations are as relevant in the cloud as they are in on-premise environments, but the methods in which to access and perform such investigations differ. This post will describe some of the challenges of bringing on-premises forensics techniques to the cloud and show one solution to overcome these challenges, using …

Scalable infrastructure for investigations and incident response Read More »

Categories: Security News

Announcing the Microsoft Edge Insider Bounty

Tue, 08/20/2019 - 12:01
This week, we released the first Beta preview of the next version of Microsoft Edge. Alongside this, Microsoft is excited to announce the launch of the Microsoft Edge Insider Bounty Program. We welcome researchers to seek out and disclose any high impact vulnerabilities they may find in the next version of Microsoft Edge, based on …

Announcing the Microsoft Edge Insider Bounty Read More »

Categories: Security News

2019 年 8 月のセキュリティ更新プログラム (月例)

Tue, 08/13/2019 - 19:05
2019 年 8 月 14 日 (日本時間)、マイクロソフトは以下のソフトウェアのセキュリティ更新プログラムを公開しました。
Categories: Security News

Patch new wormable vulnerabilities in Remote Desktop Services (CVE-2019-1181/1182)

Tue, 08/13/2019 - 13:07
Today Microsoft released a set of fixes for Remote Desktop Services that include two critical Remote Code Execution (RCE) vulnerabilities, CVE-2019-1181 and CVE-2019-1182. Like the previously-fixed ‘BlueKeep’ vulnerability (CVE-2019-0708), these two vulnerabilities are also ‘wormable’, meaning that any future malware that exploits these could propagate from vulnerable computer to vulnerable computer without user interaction. The affected …

Patch new wormable vulnerabilities in Remote Desktop Services (CVE-2019-1181/1182) Read More »

Categories: Security News

August 2019 Security Updates

Tue, 08/13/2019 - 13:05
We have released the July security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month’s security updates can be found in the Security Update Guide. As a reminder, Windows 7 and Windows Server 2008 R2 will be out of …

August 2019 Security Updates Read More »

Categories: Security News

Microsoft Announces Top Three Contributing Partners in the Microsoft Active Protections Program (MAPP)

Thu, 08/08/2019 - 23:45
Today Microsoft announced the MAPP program Top Vulnerability Contributors, Top Threat Indicator Submitters, and Top Zero-Day Reporting for the period of July 1, 2018 – June 30, 2019. The Microsoft Active Protections Program provides security and protection to customers through cooperation and collaboration with industry leading partners. While all MAPP partners have made a significant …

Microsoft Announces Top Three Contributing Partners in the Microsoft Active Protections Program (MAPP) Read More »

Categories: Security News

Announcing 2019 MSRC Most Valuable Security Researchers

Wed, 08/07/2019 - 14:30
Earlier today we announced MSRC’s 2018-2019 Most Valuable Security Researchers at Black Hat. The following 75 researchers hail from all corners of the world and possess varied experience and skills, yet all of them have contributed to securing the Microsoft’s customers and the broader ecosystem. For over a decade, one of Microsoft’s partners in vulnerability …

Announcing 2019 MSRC Most Valuable Security Researchers Read More »

Categories: Security News

Corporate IoT – a path to intrusion

Mon, 08/05/2019 - 12:27
Several sources estimate that by the year 2020 some 50 billion IoT devices will be deployed worldwide. IoT devices are purposefully designed to connect to a network and many are simply connected to the internet with little management or oversight. Such devices still must be identifiable, maintained, and monitored by security teams, especially in large …

Corporate IoT – a path to intrusion Read More »

Categories: Security News

Pages