Posted on Monday June 01, 2020 | MSRC alerts
Machine learning (ML) is an increasingly valuable tool in cyber security as adversaries continually evolve their tactics and techniques to evade detection. As machine learning has advanced and sophisticated ML models have been developed to assist security professionals in protecting the cloud, adversaries have been busy developing malware designed to evade ML models. To proactively...
Posted on Wednesday May 13, 2020 | MSRC alerts
This blog post outlines the work that Microsoft is doing to eliminate uninitialized stack memory vulnerabilities from Windows and why we're on this path. This blog post will be broken down into a few parts that folks can jump to: 1. Uninitialized Memory Background; 2. Potential Solutions to Uninitialized Memory Vulnerabilities; 3. InitAll - Automatic Initialization; 4. Interesting Findings...
Posted on Tuesday May 05, 2020 | MSRC alerts
The Azure Sphere Security Research Challenge is an expansion of Azure Security Lab, announced at Black Hat in August 2019. At that time, a select group of talented researchers was invited to come and do their worst, emulating criminal hackers in a customer-safe cloud environment. This new research challenge aims to spark new high impact...
Posted on Wednesday April 29, 2020 | MSRC alerts
Our team, DeisLabs, recently released a new piece of software called Krustlet, which is a tool for running WebAssembly modules on the popular, open-source container management tool called Kubernetes. Kubernetes is used quite extensively to run cloud software across many vendors and companies and is primarily written in the Go programming language. While there have...
Posted on Thursday April 23, 2020 | MSRC alerts
Following the second Security Researcher Quarterly Leaderboard and the 2020 MSRC Most Valuable Security Researchers criteria we published in February 2020, we are excited to announce the 2020 First Quarter (Q1) Security Researcher Leaderboard, listing our top contributing researchers for the last quarter. The top three researchers of the last quarter are: Zhiniang Peng...
Posted on Tuesday March 10, 2020 | MSRC alerts
We have released the March security updates to provide additional protections against malicious attackers. As a best practice, we encourage customers to turn on automatic updates. More information about this month's security updates can be found in the Security Update Guide.