Microsoft Security Blog

The official Microsoft blog for discussing industry and Microsoft security topics.

Browse by Tags

Tagged Content List
  • Blog Post: Cloud Computing Trends Report : Maturity of IT Departments

    As cloud computing matures, a growing number of organizations are interested in moving to cloud environments to help lower IT costs, increase efficiencies, and realize greater flexibility. However, organizations that consider cloud computing have also voiced a number of concerns. In multiple studies...
  • Blog Post: Counterfeit Software Preloaded with Malware and the Link to Botnets: Operation b70

    For years I have heard talk in the industry that much of the counterfeit software available on the Internet was preloaded with malware. How much of the counterfeit software available is preloaded with malware? What type of malware is preloaded on these systems and what does it allow the attackers to...
  • Blog Post: New Microsoft Malware Protection Center Threat Report Published: EyeStye

    Recently I wrote a three part series of articles ( part 1 , part 2 , part 3 ) on the evolving threat landscape in the European Union. As I wrote in these articles, there has been a steep rise in the malware infection rates in some European countries that typically have some of the lowest malware infection...
  • Blog Post: Weekly Roundup: May 18, 2012 – Smartphone Security, Cyber Threat Trends and the Importance of Secure Development

    Trending Security News Security news stories this week focused on smartphone security and GPS tracking; our Security Development Conference in DC; and a report on security technology trends with a few stories also covering malware stats and cyber-attacks. Here are the security news stories and two blog...
  • Blog Post: Weekly Roundup: May 4, 2012 – Think Before You Click

    Trending Security News Security news stories this week continue to validate the importance of cybersecurity skills in the marketplace and FEMA released a new National Preparedness Report providing insights on the state of national critical infrastructure protection. Here are some of the security news...
  • Blog Post: Weekly Roundup: April 27, 2012 – Tracking the Security Trends: Data Integrity

    Trending Security News Security news stories last week reported the House passed the CISPA bill; CNET reports Mac security ten years behind Microsoft; and infosecurity ran a story about the GAO that testified on Capitol Hill reporting there were 42,887 cybersecurity incidents last year. Here are some...
  • Blog Post: Weekly Roundup: April 20, 2012 – Cybersecurity R&D Trends

    Security News Security news stories this week covered CISPA, a cybersecurity bill that continues to draw fire from privacy groups: some experts weigh the pros while others say the bill is too vague as written and predict it will be tabled. Also in the news Anonymous claims Pastebin censorship and creates...
  • Blog Post: Weekly Roundup: April 13, 2012 – Data Security Trends and Issues

    Trending Security News Security news stories this week highlighted data breaches, tips on computer security, cybersecurity and online safety patterns and practices, and analysis in support and criticism of Cyber Intelligence Sharing And Protection Act (CISPA). Here’s our top news stories and blog...
  • Blog Post: Weekly Roundup: April 6, 2012 – Cybersecurity: Go Ahead, Be Defensive!

    Trending Security News Security news stories this week covered a failed attempt by Anonymous to bring down the Internet; latest malware stats for Macs; new government investments in understanding big data trends and building new cybercrime defenses; and eight UK universities who recognize excellence...
  • Blog Post: Business Round Table on Cybersecurity

    This week Business Roundtable (BRT) released its report Mission Critical: A Public-Private Strategy for Effective Cyber Security . Microsoft is an active participant in BRT and we believe this report includes key insights that can help inform and advance cybersecurity discussions that are currently happening...
  • Blog Post: The Future of Cybersecurity: Understanding How the Next Billion Users Will Change Cyberspace

    The product of human ingenuity and innovation, cyberspace now delivers a range of critical services to more citizens around the world than ever before. Yet, the online world as we know it stands at the threshold of unprecedented change. Being invited to speak at the EastWest Institute’s Worldwide...
  • Blog Post: SDL Awareness and Adoption High Among Security Professionals

    UPDATE - Hear what others are saying about this survey: (Dark Reading) Survey Says: More Than Half of Software Companies Deploying Secure Coding Methods (NetworkWorld) Code Writers Finally Get Security? Maybe (Help Net Security) Root issues causing software vulnerabilities Errata Security has released...
  • Blog Post: Be Safer - Run as Standard User

    I do my work as standard user on Windows 7, just as I did with Windows Vista.  It is not a burden.  When I need to do an admin task, I put on my “admin” hat by switching to my admin account specifically and doing my admin thing and then logging off.  I don’t browse, I don’t download stuff...
  • Blog Post: Supplemental Data for Calculating Mozilla Patching Speed

    A couple of days ago, Secunia published their Secunia 2008 Report , and one of their tables garnered quite a bit of attention with respect to Mozilla patching quickly: Brian Krebs , Washington Post, Fanning the Flames of the Browser Security Wars Brian Prince, eWeek, Security Report Ignites Firefox vs...
  • Blog Post: Feb09 Security Bulletin SDL Benefit Summary

    Summaries from previous months: Jan09 Security Bulletin SDL Benefit Summary When I do analysis and reports on Microsoft products, I typically look for where the Security Development Lifecycle (SDL) has helped to provide improvement and provide some stats on that.  This year, I decided to try and...
  • Blog Post: CIO.COM: Mozilla and “Counting Still Easy…”

    [DISCLOSURE for those who don’t read about boxes: I work for Microsoft.] I admit that I enjoy discussing issues and digging into claims to see if I can find fractures or flaws in logic. When I ran product management teams for companies in previous roles, I would always review our draft product glossies...
  • Blog Post: Brian Krebs Blog on ‘at Risk’ Chart Methodology

    I am a couple of articles into my series: Can Mozilla Support Claims of Firefox Being the Most Secure Web Browser? , and Can Mozilla Support Claims of Firefox Being the Most Secure Web Browser? (Part 2) In part 2, I probed Mozilla’s usage of an ‘at risk’ chart to claim that their customers...
  • Blog Post: CIO.COM: Can Mozilla Support Their Security Claims?

    Mozilla bills Firefox as the most secure Web browser on the planet, but is it really? Follow along with this series and see if the claims hold up to close scrutiny. Today, I started a multi-part article series on cio.com (Security landing page: http://www.cio.com/topic/1419/Security ) probing Mozilla...
  • Blog Post: SIRV5 Vulnerability Trends Webcast - 2 of 2 - Microsoft Trends

    With the recent release of v5 of the Security Intelligence Report, I decided to produce a couple of webcast videos where I present my findings to you directly in a brief presentation. In this second one, I go over the vulnerability disclosure trends for vulnerabilities affecting Microsoft products. ...
  • Blog Post: SIRv5 Vulnerability Trends Webcast - 1 of 2 - Industry Trends

    With the recent release of v5 of the Security Intelligence Report, I decided to produce a couple of webcast videos where I present my findings to you directly in a brief presentation. In this first one, I go over the industry-wide trends.   1H08 Vulnerability Trends - Part1 - Industry To see all...
  • Blog Post: Security Intelligence Report v5

    This morning, we released the latest version of the Microsoft Security Intelligence Report (SIRv5), examining industry-wide software vulnerability disclosures, Microsoft vulnerability disclosures and exploits, malicious software (malware), and potentially unwanted software. I am one of the primary contributors...
  • Blog Post: Download: H1 2008 Desktop OS Vendor Report - Vulnerabilities and Days-of-Risk

    This report looks at all of the vulnerabilities fixed by Apple, Microsoft, Red Hat and Ubuntu during the first half of 2008. At the vendor level, the report examines all vulnerabilities as well as Days of Risk (DoR) associated with those vulnerabilities. The report further drills down to examine just...
  • Blog Post: Download: Server Core Potential Security Benefit

    With Windows Server 2008, the Microsoft Windows Server team introduced a new installation option –Server Core. Server Core is a “minimal install” option of Windows Server that excludes much of the GUI and many applications – such as Internet Explorer and Windows Media Player – that would be present...
  • Blog Post: Q1 2008 - Client OS Vulnerability Scorecard

    This paper is a compilation of vulnerability data for client operating systems for the first 3 month, January through March, of 2008. Vulnerabilities and fixes for the following products are discussed: Microsoft Windows Vista Microsoft Windows XP SP2 Red Hat Enterprise Linux Desktop (v. 5 client) Red...
  • Blog Post: Windows Vista vs Windows XP SP2 Vulnerability Report 2007

    In the wake of my Windows Vista One Year Vulnerability Report , I have received many questions regarding the current vulnerability record of Windows Vista as compares with Windows XP SP2. This short paper is a compilation of vulnerability data for Microsoft Windows Vista and Microsoft Windows XP SP2...
Page 1 of 3 (61 items) 123