Posted on Monday July 29, 2019 | MSRC alerts
We're getting close to Black Hat, and we hope to see you there. Here's where you can find members of the Microsoft Security Response Center if you'd like to say hello, ask a question about a report you made, discuss a recent blog article, or just show us pictures of your dog. Wednesday, August 7...
Posted on Thursday July 25, 2019 | MSRC alerts
Today we announce the top organizational candidates for Vulnerability Top Contributors, Threat Indicator Top Submitters, and Zero-Day Top Reporting for the period of July 1, 2018 - June 30, 2019. The Microsoft Active Protections Program provides security and protection to customers through cooperation and collaboration with industry leading partners. This bi-directional sharing program of threat...
Posted on Monday July 22, 2019 | MSRC alerts
In this series, we have explored the need for proactive measures to eliminate a class of vulnerabilities and walked through some examples of memory safety issues we've found in Microsoft code that could have been avoided with a different language. Now we'll peek at why we think that Rust represents the best alternative to C...
Posted on Thursday July 18, 2019 | MSRC alerts
In our first post in this series, we discussed the need for proactively addressing memory safety issues. Tools and guidance are demonstrably not preventing this class of vulnerabilities; memory safety issues have represented almost the same proportion of vulnerabilities assigned a CVE for over a decade. We feel that using memory-safe languages will mitigate this...
Posted on Wednesday July 17, 2019 | MSRC alerts
One of Microsoft's many security investments to protect customers is in the partnerships we build with the external security research community. We are excited to announce the launch of the Dynamics 365 Bounty program and welcome researchers to seek out and disclose any high impact vulnerabilities they may find in Dynamics 365. Rewards up to...
Posted on Tuesday July 16, 2019 | MSRC alerts
What if we could eliminate an entire class of vulnerabilities before they ever happened? Since 2004, the Microsoft Security Response Centre (MSRC) has triaged every reported Microsoft security vulnerability. From all that triage one astonishing fact sticks out: as Matt Miller discussed in his 2019 presentation at BlueHat IL, the majority of vulnerabilities fixed and...