Posted on Tuesday August 13, 2019 | MSRC alerts
Today Microsoft released a set of fixes for Remote Desktop Services that include two critical Remote Code Execution (RCE) vulnerabilities, CVE-2019-1181 and CVE-2019-1182. Like the previously-fixed 'BlueKeep' vulnerability (CVE-2019-0708), these two vulnerabilities are also 'wormable', meaning that any future malware that exploits these could propagate from vulnerable computer to vulnerable computer without user interaction. The affected...
Posted on Friday August 09, 2019 | MSRC alerts
Today Microsoft announced the MAPP program Top Vulnerability Contributors, Top Threat Indicator Submitters, and Top Zero-Day Reporting for the period of July 1, 2018 - June 30, 2019. The Microsoft Active Protections Program provides security and protection to customers through cooperation and collaboration with industry leading partners. While all MAPP partners have made a significant...
Posted on Wednesday August 07, 2019 | MSRC alerts
Earlier today we announced MSRC's 2018-2019 Most Valuable Security Researchers at Black Hat. The following 75 researchers hail from all corners of the world and possess varied experience and skills, yet all of them have contributed to securing the Microsoft's customers and the broader ecosystem. For over a decade, one of Microsoft's partners in vulnerability...
Posted on Monday August 05, 2019 | MSRC alerts
Azure is exceptionally secure. To help keep it that way, we are doubling the top bounty reward for Azure vulnerabilities to $40,000. But we aren't stopping there. To make it easier for security researchers to confidently and aggressively test Azure, we are inviting a select group of talented individuals to come and do their worst...
Posted on Monday August 05, 2019 | MSRC alerts
Several sources estimate that by the year 2020 some 50 billion IoT devices will be deployed worldwide. IoT devices are purposefully designed to connect to a network and many are simply connected to the internet with little management or oversight. Such devices still must be identifiable, maintained, and monitored by security teams, especially in large...
Posted on Tuesday July 30, 2019 | MSRC alerts
Who's going to be on the Most Valuable Security Researcher list at Black Hat USA 2019? We're not announcing the names yet but this is how we'll determine who's there. How do we define the Most Valuable Security Researchers? The list at Black Hat will be the top tier of researchers based on not just the volume...