Security


Microsoft Security Guidelines for Open Source Software Adopted by OpenSSF

The Open Source Security Foundation (OpenSSF) announced on Wednesday that it has adopted the Secure Supply Chain Consumption Framework (S2C2F) for ensuring the secure use of open source software (OSS) by developers.

Microsoft Bolstering Its Attack Simulation Training Service with SANS Institute Learning Modules

Microsoft indicated last week that it'll be bringing a SANS Institute training series to Microsoft 365 Defender for Office 365 users of its Attack Simulation Training service.

Microsoft Provides Guidance on Recent OpenSSL Security Risks

Microsoft has chimed in on the highly visible OpenSSL security risks that emerged last week, and advises users start applying fixes based on OpenSSL's recent patches.

Microsoft and Yubico Preview Certificate-Based Authentication for Mobile Devices Using Security Keys

Microsoft on Wednesday announced a preview of Azure Active Directory Certificate-Based Authentication (CBA) support for Android and iOS devices using hardware security keys.

It's Time To Go Passwordless -- Here's How

Microsoft has provided the tools for you to ditch the outdated and unsecure log in tech. It's up to you to actually take advantage of it.

Microsoft Details Threat Actors Leveraging Raspberry Robin Worm

Microsoft said that a cybercriminal group has deployed Clop encryption malware on those previously affected by the Raspberry Robin worm.

Microsoft Authenticator Number Matching Security Feature Released and Coming by Default Next Year

The Microsoft Authenticator app now has a number-matching security feature at the "general availability" (GA) commercial release stage, Microsoft announced on Tuesday.

Microsoft Previews Authentication Strength Feature for Greater Control over Multifactor Authentication Access Methods

Microsoft this week announced a preview of "Authentication Strength," a new control for organizations using the Azure Active Directory Conditional Access service.

FIDO Authenticate Keynote Talk Calls for 'Radical' Industry Transparency on Multifactor Authentication Use

The Authenticate 2022 keynote talk highlighted passwordless efforts by the FIDO Alliance and called for increased multifactor authentication transparency by industry sectors.

Microsoft Server Misconfiguration Led to Exposed Customer Data

Microsoft on Wednesday confirmed that a misconfiguration with a Microsoft server endpoint has potentially exposed some customer data, including personal information and emails.

On the Floor of Microsoft Ignite: Day 1 Announcement Thoughts

Despite a smaller floor presence, Microsoft jumped out of the gate with some big announcements for IT and database managers.

Freeeway Tunnel Graphic

Microsoft 365 and Security Products Reaching General Availability at Microsoft Ignite

A lot of products were announced at the "general availability" (GA) commercial-release stage during this week's Microsoft Ignite event, which kicked off on Wednesday.

Microsoft's October Security Patch Missing Zero-Day Exchange Fix

This month's Microsoft monthly security update, which comes packed with 85 flaw fixes, is notable for what's not included – a fix for last month's publicly disclosed Exchange vulnerabilities, known as "NotProxyShell."

Microsoft Endpoint Manager Enables AOSP Android Device Management via Premium Add-On

Microsoft this week announced the ability to manage Android Open Source Project (AOSP) devices via Microsoft Intune, which is available as a "premium" add-on to Microsoft Endpoint Manager (MEM) subscribers.

Identity Theft Monitoring Offered to Microsoft 365 Consumer Users

Microsoft this week announced that a new Identity Theft Monitoring service is available to U.S. subscribers to the Microsoft 365 Personal or Microsoft 365 Family editions.

Microsoft Confirms Two Zero Day Exploits of Exchange Server

Exchange Server products are potential subject two newly disclosed "zero-day" vulnerabilities that are under exploit, Microsoft acknowledged, in a Thursday announcement.

Microsoft Authenticator Features Can Address 'MFA Fatigue Attacks'

Microsoft is urging organizations using the Microsoft Authenticator app to activate additional security functionality to protect against possible "multifactor authentication fatigue attacks," according to a Wednesday announcement.

Microsoft Enhances Phishing Protections for Windows 11, but Not Windows 10

Microsoft offered more details this week about its enhanced phishing protection technology that kicked off with the newly released Windows 11 version 22H2.

Microsoft September Patch Bundle Addresses 64 Vulnerabilities

Microsoft has released its September bundle of security patches, addressing about 64 common vulnerabilities and exposures (CVEs).

Why Immutable Backup Storage Isn't Enough Protection Against Ransomware

To truly protect your data from attackers, take some time to follow these additional safeguards.

Subscribe on YouTube