Security


Microsoft's September Security Updates Include Zero-Day Fix

Microsoft's September security updates, released on Tuesday, included a fix for a zero-day local privilege escalation flaw that was disclosed with lots of drama last month.

One Way Office 365 Phishing Attacks Are Getting Sneakier

A relatively new type of phishing attack is targeting Office 365 users while completely circumventing all of the usual security defenses.

Project VAST Security Tool Now Rolling Out to Microsoft Premier Customers

Microsoft's Project VAST is now a supported product that's offered to Microsoft Premier customers, Microsoft announced last week.

Microsoft Highlights Security SDN Capabilities in Windows Server 2019

Microsoft is touting software-defined networking security capabilities in the coming Windows Server 2019 product.

Zero-Day Local Privilege Escalation Flaw Confirmed in Window 10 Systems

A zero-day flaw was disclosed on Monday regarding the Windows Task Scheduler in 64-bit Windows 10 and Windows Server 2016 systems for which there are no known patches or specific workarounds.

Microsoft Previews Authenticator Companion App for Apple Watch

Microsoft on Monday announced a preview of the Microsoft Authenticator companion app for use on the Apple Watch.

Intel Issues Security Advisory on L1 Speculative Execution Attack Method

Intel, Microsoft and Red Hat issued security advisories on Tuesday for yet another speculative execution side-channel attack method, this time going by the "L1 Terminal Fault" name.

Microsoft Previews Password Alternative in Edge Browser

Microsoft announced on Monday that its Microsoft Edge browser now supports the Web Authentication spec at the preview stage.

Microsoft Admits July 10 Patches Caused Skype and Exchange Server Problems

Microsoft's July 10 "update Tuesday" patches negatively affected organizations using Lync Server 2013, Skype for Business Server 2015 and Exchange Server, Microsoft admitted this week.

Microsoft Suggests Its Software Not Affected by Latest Spectre Attack Method

Researchers disclosed a new variant 1-type Spectre attack method earlier this week, but Microsoft's software apparently isn't affected by it.

Microsoft Issues Advisory on Lazy Floating Point State Restore Security Issue

Microsoft earlier this month issued an advisory for the "lazy floating point state restore" security problem (CVE-2018-3665) that potentially could affect users of Windows and Intel Core processors.

Azure AD Admins To Get Multifactor Authentication by Default

Microsoft is bringing multifactor authentication (MFA) to organizations that manage Azure Active Directory tenancies.

Password Protection and Smart Lockout Previews Now Available for Azure AD Users

Microsoft this week announced the previews of two password security capabilities for organizations using the Azure Active Directory service or Windows Server Active Directory.

Intel Issues Advisory on Lazy Floating Point Speculative Execution Flaw

This week, yet another speculative execution processor vulnerability was uncovered, namely "lazy floating point state save/restore."

Top Security Mistakes that IT Admins Make (And How To Avoid Them)

Microsoft MVP Orin Thomas lays out the most common security pitfalls IT administrators face, and how everything from the cloud to company management can make them worse.

Study: IT Orgs Bullish on AI and DevOps, Shifting on Cloud, But Challenged by Security

A new study released this week by IT security company BeyondTrust polled opinions about emerging technologies and cloud use, but it also found that traditional security concerns were top of mind for organizations.

Office 365 Threat Intelligence Service Now Has Threat Tracker Capability

Microsoft on Wednesday announced the general availability of Threat Tracker for the Office 365 Threat Intelligence service.

Microsoft Cloud App Security Now Detects GDPR Noncompliance

The Microsoft Cloud App Security service now can detect applications that fall out of compliance with the European Union's General Data Protection Regulation (GDPR) privacy law, Microsoft announced this week.

Intel and Microsoft Releasing Updates for New Speculative Execution-Type Attacks

Intel Corp. and Microsoft on Monday disclosed two additional speculative execution side-channel attack methods, potentially affecting the security of most processors in computers of all types.

Microsoft Rolls Out SQL Advanced Threat Protection

Microsoft this week announced SQL Advanced Threat Protection, which is described as "a new security package" for Azure SQL Database users.

Subscribe on YouTube