Security


Microsoft Urges LDAP Workaround Fix for Windows Systems

Microsoft updated an August security advisory this week to urge organizations using the Lightweight Directory Access Protocol in supported Windows systems to implement some configuration changes manually.

Microsoft Addresses 85 Vulnerabilities in September Security Release

Microsoft released security patches for multiple vulnerabilities in Windows and various applications in its September "update Tuesday" release.

Confidential Computing Consortium Formed To Protect Processed Data

A new Confidential Computing Consortium was announced on Wednesday by the Linux Foundation to boost the security of processed data.

Microsoft Warns of Possible August Update Troubles for Some Windows 7 and Windows Server 2008 Users

Microsoft warned this week in a Twitter post that its August security updates won't install for users of Windows 7 Service Pack 1 or Windows Server 2008 R2 SP1 if those operating system lack certain March updates.

Microsoft's August Security Patches Address New RDP Vulnerabilities

Microsoft's August security updates address about 93 common vulnerabilities and exposures, several of which are associated with Remote Desktop Protocol (RDP).

Microsoft Warns That Attackers Have Access to BlueKeep Exploit Code

Microsoft indicated recently that "BlueKeep" exploit code for Windows systems is now "widely available" for use by attackers.

How To (Safely) Run Untrusted Applications in Windows 10

The new Sandbox feature in Windows 10 lets organizations run potentially risky executables in isolation, without having to set up a virtual machine.

Remote Desktop Protocol Is a Big Target for Attackers, Study Finds

Remote Desktop Protocol is an easy-to-find and popular target for remote attackers, according to a recent study conducted by Sophos.

Microsoft Lists Some Organizational Obstacles to Eliminating Passwords

Organizations wanting a future without passwords will likely face some hurdles getting there, Microsoft admitted in an announcement this week.

Gray Fence Graphic

Windows Defender Application Guard: First Look

Of the many security improvements Microsoft made to the latest Windows 10 release, the ability to wall-off the Edge browser against malware attacks is one of the most critical.

Microsoft Previews Azure Active Directory FIDO2 Sign-Ins Without Passwords

Microsoft on Wednesday announced the availability of a public preview of Azure Active Directory's FIDO2 support, which enables user authentications without passwords.

Microsoft July Security Release Addresses 16 Critical Vulnerabilities

Microsoft on Tuesday released its July security patch bundle, which addresses about 77 common vulnerabilities and exposures across various Microsoft products.

SQL Server 2008/R2 No Longer Getting Security Patch Support

Microsoft issued some reminders this week that July 9, 2019, is the last day of patch support for SQL Server 2008 and SQL Server 2008 R2.

Microsoft Isn't Patching Excel Dynamic Data Exchange Attack Vulnerability

The Microsoft Excel spreadsheet program, in combination with its Power Query data-fetching component, can be leveraged in so-called "Dynamic Data Exchange" (DDE) types of attacks.

Cloud Services Use on the Rise But Security Concerns Remain

A recently published industry report suggested that use of public cloud services by organizations may nearly double in the next two years.

OneDrive Users To Get Storage Options, Plus New Personal Vault

Microsoft announced a few OneDrive enhancements, including storage-option additions, plus a new "Personal Vault" feature for added security assurance.

Microsoft Suggests Disabling Old Protocols with Exchange Server 2019

Exchange Server 2019 with Cumulative Update 2 (CU2) can help organizations rid themselves of old authentication protocols, which constitute a potential security risk.

Microsoft Previews Azure Bastion Service for Private VM Access

Microsoft on Tuesday announced a preview of the Azure Bastion service, which lets a user connect to an Azure virtual machine (VM) using a private Internet connection.

RAMBleed Side-Channel Attack Method Disclosed by Researchers

Academic researchers this week published information about another side-channel attack method, called "RAMBleed," that can expose information from memory chips, including encryption key information.

Microsoft 365 Business Tenants Getting Conditional Access and Trouble-Ticket Features

Microsoft added its conditional access security service to Microsoft 365 Business subscriptions, according to a Wednesday announcement, and it also added new trouble-ticket features for Microsoft 365 administrators.

Subscribe on YouTube