News

Microsoft: Beware Bogus Bulletins

In an otherwise light week for infrastructure security news, Microsoft issued a reminder to customers to beware of bogus security bulletins that look like they come from Microsoft.

The note, posted on the TechNet security site on April 3, doesn't appear to be tied to any specific incident. "From time to time malicious individuals circulate e-mails that purport to be a Microsoft Security Bulletin or Patch."

Microsoft provided several clues that a bulletin is bogus:

  • Above all, Microsoft never attaches a patch to security e-mails or provides a direct link to the patch (the links always refer to the bulletin itself, which then links to the patch.) Any e-mail that says it's from Microsoft and includes a patch or a link to a patch should be deleted immediately.
  • Each patch has a digital signature. The key is published at www.microsoft.com/technet/security/bulletin/notify.asp.
  • The authoritative version of each bulletin is also posted on Microsoft's Security Web site. If there's any doubt that a bulletin is real, check it there: www.microsoft.com/technet/security/Default.asp.

    The entire Microsoft notice, a good resource to forward to all users, is available here: www.microsoft.com/technet/security/news/patch_hoax.asp.

  • About the Author

    Scott Bekker is editor in chief of Redmond Channel Partner magazine.

    Featured

    • SameSite Cookie Changes Rolled Back Until Summer

      The Chromium Project announced on Friday that it's delaying enforcement of SameSite cookie changes, and is temporarily rolling back those changes, because of the COVID-19 turmoil.

    • Basic Authentication Extended to 2H 2021 for Exchange Online Users

      Microsoft is now planning to disable Basic Authentication use with its Exchange Online service sometime in the "second half of 2021," according to a Friday announcement.

    • Microsoft Offers Endpoint Configuration Manager Advice for Keeping Remote Clients Patched

      Microsoft this week offered advice for organizations using Microsoft Endpoint Configuration Manager with remote Windows systems that need to get patched, and it also announced Update 2002.

    • Azure Edge Zones Hit Preview

      Azure Edge Zones, a new edge computing technology from Microsoft designed to enable new scenarios for developers and partners, emerged as a preview release this week.

    comments powered by Disqus

    Office 365 Watch

    Sign up for our newsletter.

    Terms and Privacy Policy consent

    I agree to this site's Privacy Policy.