Security


Microsoft Offers More 'Solorigate' Advice Using Microsoft 365 Defender Tools

Microsoft issued yet another article with advice on how to use its Microsoft 365 Defender suite of tools to protect against "Solorigate" advanced persistent threat types of attacks in a Thursday announcement.

Windows Server Update Services Users Getting Proxy-Use Change This Month

Microsoft on Tuesday notified Windows Server Update Services (WSUS) users that it's no longer going to automatically support "user proxies" to get patches from Microsoft's content delivery networks (CDNs), starting with this month's cumulative update release.

Microsoft Delivers Fixes for 83 Vulnerabilities in January Security Patch Bundle

Microsoft released its January security patch bundle on Tuesday, delivering fixes for 83 common vulnerabilities and exposures (CVEs).

Microsoft Defender for Endpoint Gets Linux Server Forensics Capabilities

Microsoft Defender for Endpoint now has an endpoint detection and response (EDR) capability for use with Linux servers that's deemed ready for use in production environments, Microsoft indicated on Monday.

Security Q&A: A (Very Slight) Upside to Solorigate and Top Blue Team Attack Tools

Security expert Sergey Chubarov on the current security landscape and how the SolarWinds attack can change cybersecurity for the better.

CISA Points to APT Attack Methods Besides 'Solorigate' that Affected Microsoft 365, Azure Services

An advanced persistent threat actor associated with the SolarWinds Orion attacks used their ability to create credentials to compromise a victim's Microsoft 365 and Azure services, but they didn't always tap the so-called "Solorigate" vulnerability to do so.

U.S. National Security Agency Offers Advice on Blocking Obsolete TLS

The U.S. National Security Agency this month published an advisory on detecting and blocking old and insecure Transport Layer Security (TLS) protocol use by organizations.

Office 365 Attack Simulation Training Capability Now Commercially Available

Microsoft this week announced the commercial release of a feature that simulates phishing attacks, which is now available to certain subscribers to the Microsoft Defender for Office 365 service.

Microsoft Activating One-Time Passcode Feature in March for Azure Users

Microsoft is planning to turn on a one-time passcode feature in March that will grant temporary network access to business collaborators for organizations that use the Azure Active Directory B2B service.

Microsoft Offers Security Advice After 'Solorigate' Attacks

Microsoft described security measures for IT pros to consider in the wake of the SolarWinds Orion-based software attack.

Revisiting My Tech Predictions for 2020

To be fair, who could have predicted any of this?

Microsoft Previews Password Storage via the Microsoft Authenticator App

Microsoft this week announced a preview of a user name and password autofill capability in the Microsoft Authenticator app.

Emergency Directive Issued on SolarWinds Orion Software Compromise by Nation-State Actors

The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive this week for federal agencies using SolarWinds Orion management software, which has been compromised in a sophisticated attack.

Microsoft Addresses 58 Vulnerabilities in December Patch Bundle

Microsoft on Tuesday released its December security bundle of software fixes, consisting of just 58 patches, according to the counts of security researchers.

Microsoft Promises Greater PC Security with Coming Pluton Processors

Microsoft has introduced Pluton, a security solution aiming to make the current root of trust between the central processing unit and the trusted platform module in devices more resistant to physical tampering.

Microsoft Extended Security Update Program Approaches Year 2

Microsoft this week announced that the Windows 7 and Windows Server 2008 Extended Security Update (ESU) program is approaching Year 2.

Microsoft Endpoint Data Loss Protection Now Commercially Released

The Microsoft Endpoint Data Loss Prevention service, used to protect data accessed on devices, reached "general availability" commercial-release status, Microsoft announced this week.

Microsoft's November Security Bundle Addresses 112 Vulnerabilities

Microsoft released its November bundle of security patches on Tuesday, addressing 112 common vulnerabilities and exposures (CVEs).

Microsoft Launches Revamped Security Update Guide

Microsoft on Monday described the format of its newly improved "Security Update Guide," which is used to see monthly security patch details.

Microsoft Changes Privacy Platform Name to SmartNoise

Microsoft Research has changed the name of its "differential privacy" platform from "WhiteNoise" to "SmartNoise," according to a Wednesday announcement.

Subscribe on YouTube