Posted on Monday July 29, 2019 | MSRC alerts
We deeply appreciate the partnership of the many talented security researchers who report vulnerabilities to Microsoft through Coordinated Vulnerability Disclosure. We pay bounties for research in key areas, and each year at Black Hat USA, we've recognized the most impactful researchers helping to protect the ecosystem. That's not changing; we're continuing to expand our bounty...
Posted on Monday July 29, 2019 | MSRC alerts
We're getting close to Black Hat, and we hope to see you there. Here's where you can find members of the Microsoft Security Response Center if you'd like to say hello, ask a question about a report you made, discuss a recent blog article, or just show us pictures of your dog. Wednesday, August 7...
Posted on Thursday July 25, 2019 | MSRC alerts
Today we announce the top organizational candidates for Vulnerability Top Contributors, Threat Indicator Top Submitters, and Zero-Day Top Reporting for the period of July 1, 2018 - June 30, 2019. The Microsoft Active Protections Program provides security and protection to customers through cooperation and collaboration with industry leading partners. This bi-directional sharing program of threat...
Posted on Monday July 22, 2019 | MSRC alerts
In this series, we have explored the need for proactive measures to eliminate a class of vulnerabilities and walked through some examples of memory safety issues we've found in Microsoft code that could have been avoided with a different language. Now we'll peek at why we think that Rust represents the best alternative to C...
Posted on Thursday July 18, 2019 | MSRC alerts
In our first post in this series, we discussed the need for proactively addressing memory safety issues. Tools and guidance are demonstrably not preventing this class of vulnerabilities; memory safety issues have represented almost the same proportion of vulnerabilities assigned a CVE for over a decade. We feel that using memory-safe languages will mitigate this...
Posted on Wednesday July 17, 2019 | MSRC alerts
One of Microsoft's many security investments to protect customers is in the partnerships we build with the external security research community. We are excited to announce the launch of the Dynamics 365 Bounty program and welcome researchers to seek out and disclose any high impact vulnerabilities they may find in Dynamics 365. Rewards up to...