Sign in
Roger's Security Blog
As Chief Security Advisor of Microsoft EMEA - lets share interesting security information
Tags
Advisory
Anti-Malware
Applications
Architecture
Behaviour
Botnet
Browsing
Chat
Chief Security Advisor
Children
Cloud
Cloud Computing
Collaboration
Competition
Compliance
Consumer
Cost
Crime
Critical Infrastructure
Critical Infrastructure Protection
Cybercrime
Cybersecurity Agenda
Data Protection
Development Lifecycle
Ecosystem
Encryption
Event
Events/Training
Family
Freedom of Speech
Fun
Gaming
Google
Government
Hacking
Home
Identity
Identity Theft
Incident Response
Incident Sharing
Incidents
Industry
Industry Associations
internet explorer
Interoperability
Law Enforcement
Legislation
Lifecycle
Malware
Mass Mailer
Messaging
Microsoft
Microsoft Products
Mindset
Mobile
Network
NGO
Online Safety
OpenSource
Passwrods
Patch Management
People
Phone
Piracy
Policies
Policy
Policy Makers
Politics
Privacy
Processes
Products
Protection
Real Life
Research
Risk Assessment
Risk Management
Securing My Infrastructure
Security
Security Intelligence Report
Security Updates
Social Engineering
Social Media
Strategy
Support
TechEd EMEA
TechEd-ITForum
Technology
Teens
Terrorism
Trends
Trip
Trust
Trustworthy Computing
UN
University
Updates
Vulnerabilities
Windows
Windows Phone
XBox
Browse by Tags
TechNet Blogs
>
Roger's Security Blog
>
All Tags
>
security updates
Tagged Content List
Blog Post:
Security Updates and Exploit Code
rhalbheer
In our last update cycle we published the security bulletin MS12-020 Vulnerabilities in Remote Desktop Could Allow Remote Code Execution . Relatively soon after the release, there was a public exploit code available - we informed here: Proof-of-Concept Code available for MS12-020 . This would not necessarily...
on
19 Mar 2012
Blog Post:
10 Years of Trustworthy Computing at Microsoft
rhalbheer
Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this...
on
12 Jan 2012
Blog Post:
Implementing the Top 4 Defense Strategies
rhalbheer
The Australian Defense Signals Directorate maintains a list of the Top 35 Mitigation Strategies against targeted intrusions. This is just a reference to the top strategies: Patch Applications Patch the Operating System Minimize the use of local admin Application whitelisting … Looking at these 35 strategies...
on
13 Dec 2011
Blog Post:
Security of Car Software
rhalbheer
We have seen some of the attacks recently, where people started to attack either the locks or the technology/software in the car itself controlling the chassis etc. On DarkReading I was just reading this article: Car Systems Reminiscent of Early PCs One of the things I do not get with cars is the way...
on
9 Sep 2011
Blog Post:
Microsoft Security Update Guide, Second Edition
rhalbheer
A while ago we released the Microsoft Security Update Guide to explain how we release security updates and how you should/could work with our updates. It encompasses these themes: Get to know the security update release process Learn how to evaluate risk See how to mitigate security risks Understand...
on
28 Mar 2011
Blog Post:
On the effectiveness of DEP and ASLR
rhalbheer
Our Security Research and Defense team published a blog post, which is really interesting to read to understand how to protect Windows Vista and Windows 7: On the effectiveness of DEP and ASLR . There is a lot of information on how both raise the bar for attackers. These are the key take away: DEP and...
on
9 Dec 2010
Blog Post:
The Risks of Unofficial Patches
rhalbheer
This is quite a normal scenario: A zero-day pops up on the Internet by a security researcher. Immediately afterwards we see the first exploits appearing and being integrated into the different attack tools. Now, the race started: The vendor has to develop a security update, the criminals try to exploit...
on
17 Sep 2010
Blog Post:
Assessing the risk of the August security updates
rhalbheer
This month it is pretty important to read the Security Research and Defense blog post: Assessing the risk of the August security updates It might help you to get an overview on the biggest release ever Roger
on
10 Aug 2010
Page 1 of 1 (8 items)