No Image

Microsoft Launches a New Recognition Program for MAPP Partners

2019-05-30 KENNETH 0

Microsoft Launches a New Recognition Program for MAPP Partners There are many dedicated people and organizations who contribute to the protection and security of our common customers. For years, Microsoft has recognized security researchers for helping protect the ecosystem. Now, we’re announcing the launch of a new program to better recognize and thank Microsoft Active Protections Program (MAPP) partners for all they do to protect our customers, including awards and evangelism based on their contributions. MAPP provides better protections for customers through: Early access to monthly security release information, allowing partners to proactively apply protections prior to the release date Sharing of threat indicators Reporting vulnerabilities in Microsoft products and following Coordinated Vulnerability Disclosure (CVD) In the last six months, MAPP partners have provided 430 unique vulnerability reports and submitted nearly 158 million threat indicators. This data helps Microsoft harden [ more… ]

No Image

Prevent a worm by updating Remote Desktop Services (CVE-2019-0708)

2019-05-15 KENNETH 0

Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) Today Microsoft released fixes for a critical Remote Code Execution vulnerability, CVE-2019-0708, in Remote Desktop Services – formerly known as Terminal Services – that affects some older versions of Windows. The Remote Desktop Protocol (RDP) itself is not vulnerable. This vulnerability is pre-authentication and requires no user interaction. In other words, the vulnerability is ‘wormable’, meaning that any future malware that exploits this vulnerability could propagate from vulnerable computer to vulnerable computer in a similar way as the WannaCry malware spread across the globe in 2017. While we have observed no exploitation of this vulnerability, it is highly likely that malicious actors will write an exploit for this vulnerability and incorporate it into their malware.  Now that I have your attention, it is important that affected systems are patched as quickly as possible to prevent such a scenario from happening. In response, we are taking the unusual step of providing a security update [ more… ]

No Image

May 2019 Security Update Release

2019-05-15 KENNETH 0

May 2019 Security Update Release Today, we released security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month’s security updates can be found on the Security Update Guide. Source: May 2019 Security Update Release

No Image

April 2019 Security Update Release

2019-04-10 KENNETH 0

April 2019 Security Update Release Today, we released security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month’s security updates can be found on the Security Update Guide. Tags Security Advisory Security Update Update Tuesday Source: April 2019 Security Update Release

Microsoft Bounty Program Updates: Faster bounty review, faster payments, and higher rewards

2019-04-03 KENNETH 0

Microsoft Bounty Program Updates: Faster bounty review, faster payments, and higher rewards In 2018 The Microsoft Bounty Program awarded over $2,000,000 to encourage and reward external security research in key technologies to protect our customers. Building on that success, we are excited to announce a number of improvements in our bounty programs to better serve the security research community.   Faster bounty review – As of January 2019, the Cloud, Windows, and Azure DevOps programs now award bounties upon completion of reproduction and assessment of each submission, rather than waiting until the final fix has been determined. Shortening the time from submission to award determination is just one way we will get bounty rewards to researchers faster.     Faster bounty payments, with more payment options – Once a vulnerability submission has successfully qualified for bounty award, we want to ensure payments happen [ more… ]