Posted on Saturday June 15, 2019 | MSRC alerts
This week, MSRC confirmed the presence of an active Linux worm leveraging a critical Remote Code Execution (RCE) vulnerability, CVE-2019-10149, in Linux Exim email servers running Exim version 4.87 to 4.91. Azure customers running VMs with Exim 4.92 are not affected by this vulnerability. Azure has controls in place to help limit the spread of this...
Posted on Tuesday June 11, 2019 | MSRC alerts
Today, we released security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month's security updates can be found on the Security Update Guide.
Posted on Friday May 31, 2019 | MSRC alerts
On May 14, Microsoft released fixes for a critical Remote Code Execution vulnerability, CVE-2019-0708, in Remote Desktop Services - formerly known as Terminal Services - that affects some older versions of Windows. In our previous blog post on this topic we warned that the vulnerability is 'wormable', and that future malware that exploits this vulnerability...
Posted on Friday May 31, 2019 | MSRC alerts
Earlier this week BlueHat Shanghai brought together security researchers and hundreds of cybersecurity professionals from China and across Asia to explore the latest topics in cybersecurity research. Including presentations from Qihoo 360, Baidu, Alibaba and the Chinese Academy of Sciences, BlueHat Shanghai highlighted incredibly talented Chinese researchers and focused on cutting edge topics including container...
Posted on Thursday May 30, 2019 | MSRC alerts
There are many dedicated people and organizations who contribute to the protection and security of our common customers. For years, Microsoft has recognized security researchers for helping protect the ecosystem. Now, we're announcing the launch of a new program to better recognize and thank Microsoft Active Protections Program (MAPP) partners for all they do to...
Posted on Tuesday May 14, 2019 | MSRC alerts
Today, we released security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month's security updates can be found on the Security Update Guide.