Security


Studies Offer Glimpses into Remote Work Security Practices

A couple of industry-sponsored studies on security practices associated with supporting remote workforces were recently published this week.

Exchange Server Hafnium Mitigations Available via Microsoft Defender Antivirus

Microsoft on Thursday clarified that organizations running Exchange Server can get automatic security mitigations against Hafnium attacks via Microsoft Defender Antivirus.

Microsoft Guide Describes Exchange Server Indicator of Compromise Testing Tools

The Microsoft Security Response Center team on Tuesday issued "Guidance for Responders," which provides more advice on how organizations can respond to the recent attacks that are leveraging Exchange Server zero-day flaws.

How To Review Your User Access Control Settings -- And Why

Once universally loathed, UAC is now a very useful tool for blocking Windows security threats. Here's how to make sure you're using it appropriately.

Microsoft Releases Exchange On-Premises Mitigation Tool to Address Hafnium Attacks Quickly

Microsoft on Tuesday announced the release of a one-click tool to apply temporary security protections against the recent Exchange Server attacks from the "Hafnium" advanced persistent threat group and other attackers.

Bridgt Tunnel

Working with Secure Enclaves in Azure SQL Database

Microsoft announced a lot of Azure SQL news at Ignite this month, but few as critical to application development security than the public preview of Always Encrypted with secure enclaves. Here's how to get started with this new feature.

Microsoft Warns Unpatched Exchange Servers Subject to 'DearCry' Ransomware

Exchange Servers are getting attacked to install ransomware, dubbed "DearCry," Microsoft warned on Thursday.

CISA and FBI Issue Joint Advisory on Exchange Server Hafnium Attacks

The U.S. Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation announced a Microsoft Exchange Server joint advisory that offers consolidated advice for Exchange Server users on detecting Hafnium attacks.

Microsoft Delivers Patches for 89 Vulnerabilities in March Security Release

Microsoft has released software security updates addressing 89 common vulnerabilities and exposures (CVEs), according to security researchers.

Creating an Anti-Malware Policy for Microsoft 365

Those with a business or enterprise subscription to Microsoft 365 have the option to create a policy that will greatly reduce the chances of a user becoming infected from a malicious e-mail.

Microsoft Issues Hafnium Security Fixes that Don't Require Latest Exchange Server Cumulative Updates

Microsoft's Exchange team on Monday announced additional help for organizations having trouble trying to patch Exchange Server products quickly in response to the Hafnium attacks.

Microsoft and Security Researchers Describe Tips and Tools for Detecting Exchange Server Hafnium Attacks

Microsoft has updated its recommendations to organizations running Exchange Server, targeted in Hafnium nation-state attacks, by describing some new resources.

Protecting Users Against E-Mail Phishing Attacks

Microsoft's go-to solution for anti-phishing protection is an anti-phishing policy. Here's how to create one in Microsoft 365.

Microsoft Drops 'Solorigate' for 'Nobelium' in Ongoing SolarWinds Attack Investigations

Microsoft this week described "three new pieces" of malware that were used in the SolarWinds Orion espionage attacks dubbed "Solorigate," although Microsoft security researches are now calling it "Nobelium."

How To Reclaim Your Privacy from Windows 10, Part 2

These are the top four privacy settings to check in your Windows device to make sure Microsoft doesn't collect any data you don't want it to.

Microsoft Releases Out-of-Band Security Patches for Exchange Server

Microsoft on Tuesday released out-of-band security patches for Exchange Server to address multiple zero-day flaws that are currently being exploited in active attacks.

How To Reclaim Your Privacy from Windows 10, Part 1

To audit all of the personal data that Microsoft has collected from your PC usage habits, look no further than Windows 10's Privacy Dashboard.

CrowdStrike Exec Points to Active Directory 'Structural Problems' in Senate Solorigate Hearing

Microsoft's Active Directory authentication solution got notably skewered during a Feb. 23 U.S. Senate hearing on the SolarWinds Orion software hack.

Microsoft Releases CodeQL for Detecting Solorigate Tampering

Microsoft announced on Thursday that its CodeQL queries, which were used to detect possible compromise in its source code after the Solorigate attacks, are now publicly available at the GitHub repository.

Microsoft Increasing Intune and EMS 'Standalone' Prices in July

Microsoft last week announced plans to increase the price of "standalone" subscriptions to its Microsoft Intune and Microsoft Enterprise Mobility plus Security (EMS) products starting in July.

Subscribe on YouTube

Upcoming Training Events