Security


Microsoft Entra Permissions Management Service Now Commercially Available

The Microsoft Permissions Management service, used for ensuring proper access permissions across cloud services, is now commercially available, according to a Thursday Microsoft announcement.

Microsoft Commercially Releases Windows Autopatch

Microsoft on Monday announced that its new Windows Autopatch service is now commercially available.

Microsoft Reverses Office Macro Blocking Decision

Microsoft has quietly reversed an earlier decision to block Internet macros by default in Office.

Microsoft Highlights Protections Against NTLM Relay Attack Variant DFSCoerce

Microsoft on Friday noted that a new "PetitPotam" NT LAN Manager (NTLM) relay attack variant called "DFSCoerce" is addressed if organizations followed its earlier advice in Knowledge Base article KB5005413.

AMD Data Held by Cyber Criminal Group RansomHouse

According to claims made by the cybercriminal group RansomHouse, the group is in possession of data stolen from Santa Clara, Calif.-based chip maker AMD.

Microsoft Defender Vulnerability Management Now Reports CVEs Lacking Fixes

Microsoft is previewing the ability for organizations to see when software lacks fixes for common vulnerability and exposures (CVEs), as described in a Monday announcement.

Survey: Support for Zero Knowledge Proofs in Web3 Growing

The cryptography practice of proving and validating information without revealing the data behind the information -- known as zero knowledge proofs (ZKP) -- is the key to securing and growing Web3 and the metaverse, a recent survey found.

CISA, NSA and Other Agencies Recommend Hardening PowerShell

Government cybersecurity organizations on Tuesday announced guidelines for using Microsoft's built-in PowerShell scripting language with Windows, without having it also be leveraged by attackers.

Microsoft Adds New Capabilities to Verified ID Preview

Microsoft on Tuesday announced improvements to the preview of the Microsoft Entra Verified ID service.

Microsoft Secured-Core IoT and Edge Devices Now Available

Microsoft has brought its Secured-core security design to Internet of Things (IoT) and edge devices, according to a Monday announcement.

Exchange Tenancies Should Prep for iOS Device 'Modern Authentication' Shift

Microsoft and Apple are working together to eliminate Basic Authentication use with the Mail app for organizations using the Microsoft Exchange Online e-mail service, according to a Thursday Microsoft announcement.

Microsoft Defender for Individuals App Released to Consumer Users

Microsoft has released a new security application for consumer subscribers to the Microsoft 365 Personal or Microsoft 365 Family product suites, as described in a Thursday announcement.

Q&A with Nestori Syynimaa: Don't Neglect On-Prem Security

Cloud security in a growing work-from-home landscape should not be IT's only focus.

Orca Security Discloses How It Breached Azure Synapse Customer Accounts

Orca Security on Tuesday published its findings on a security hole in Azure Synapse, as well as Azure Data Factory, that permitted access to customer tenancy accounts on Microsoft's shared "cloud" infrastructure.

'Follina' Fix Issued in Microsoft's June Patch Tuesday

Microsoft on Tuesday released 55 patches for its monthly security update release.

Microsoft Buying Foreign Attack Research Firm Miburo

Microsoft on Tuesday announced the acquisition of Miburo, a research firm that specializes in detecting and responding to foreign cyberattacks.

Three Microsoft Workload Identities Capabilities Now at Production Use Stage

Three capabilities in the Microsoft Entra Workload Identities service are "ready now for production use," according to a Thursday Microsoft announcement.

Cloud Security Top Concern at RSA Conference

Security experts attending this year's RSA Conference in San Francisco said their top concern for their enterprises is cloud security.

Microsoft Previews New Upgrade Readiness Reports in Microsoft Endpoint Manager

The Microsoft Endpoint Manager Admin Center portal now offers previews of reports designed to assess Windows client device feature update readiness, plus the risks associated with specific operating system upgrades, per this Wednesday announcement.

Microsoft Defender for Endpoint Can Now Block Bad Unmanaged Devices

Microsoft Defender for Endpoint users now have a new "Contain" feature for compromised devices, Microsoft announced on Thursday.

Subscribe on YouTube