Sign in
Microsoft Security Blog
The official Microsoft blog for discussing industry and Microsoft security topics.
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
TechNet Blogs
>
Microsoft Security Blog
Follow Us
RSS for Posts
@msftsecurity
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftsecurity
Monthly Archives
Archives
May 2013
(5)
April 2013
(8)
March 2013
(6)
February 2013
(10)
January 2013
(13)
December 2012
(7)
November 2012
(7)
October 2012
(9)
September 2012
(11)
August 2012
(13)
July 2012
(7)
June 2012
(6)
May 2012
(13)
April 2012
(10)
March 2012
(21)
February 2012
(7)
January 2012
(7)
December 2011
(9)
November 2011
(8)
October 2011
(7)
September 2011
(13)
August 2011
(12)
July 2011
(9)
June 2011
(5)
May 2011
(5)
April 2011
(1)
March 2011
(7)
February 2011
(5)
December 2010
(1)
May 2010
(1)
April 2010
(2)
March 2010
(16)
February 2010
(3)
December 2009
(1)
November 2009
(1)
September 2009
(1)
July 2009
(2)
June 2009
(3)
April 2009
(8)
March 2009
(2)
February 2009
(4)
January 2009
(2)
December 2008
(1)
November 2008
(4)
October 2008
(1)
September 2008
(1)
August 2008
(5)
June 2008
(5)
May 2008
(4)
April 2008
(6)
March 2008
(4)
February 2008
(1)
January 2008
(1)
December 2007
(1)
November 2007
(5)
October 2007
(5)
September 2007
(2)
August 2007
(1)
July 2007
(1)
June 2007
(7)
May 2007
(4)
April 2007
(1)
March 2007
(4)
February 2007
(10)
January 2007
(10)
December 2006
(1)
November 2006
(6)
October 2006
(11)
September 2006
(7)
August 2006
(5)
July 2006
(9)
June 2006
(9)
May 2006
(10)
April 2006
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Security Blog
Download: Windows Vista One Year Vulnerability Report
Posted
over 5 years ago
by
Jeff Jones - MSFT
63
Comments
Windows Vista shipped to business customers on the last day of November 2006, so the end of November 2007 marks the one year anniversary for supported production use of the product. This paper analyzes the vulnerability disclosures and security updates for the first year of Windows Vista and looks at it in the context of its predecessor, Windows XP, along with other modern workstation operating systems Red Hat, Ubuntu and Apple products. The results of the analysis show that Windows Vista has an...
Microsoft Security Blog
Q1 2008 - Client OS Vulnerability Scorecard
Posted
over 5 years ago
by
Jeff Jones - MSFT
38
Comments
This paper is a compilation of vulnerability data for client operating systems for the first 3 month, January through March, of 2008. Vulnerabilities and fixes for the following products are discussed: Microsoft Windows Vista Microsoft Windows XP SP2 Red Hat Enterprise Linux Desktop (v. 5 client) Red Hat Enterprise Linux WS (V. 4) Ubuntu 6.06 LTS Desktop Apple Mac OS X 10.5 (Leopard) Apple Mac OS X 10.4 (Tiger) For January through March of 2008, Mac OS X users experienced the highest number of vulnerabilities...
Microsoft Security Blog
CIO.COM: Can Mozilla Support Their Security Claims?
Posted
over 4 years ago
by
Jeff Jones - MSFT
28
Comments
Mozilla bills Firefox as the most secure Web browser on the planet, but is it really? Follow along with this series and see if the claims hold up to close scrutiny. Today, I started a multi-part article series on cio.com (Security landing page: http://www.cio.com/topic/1419/Security ) probing Mozilla’s claims of security superiority. My plan is to post up a new article every few days probing aspects of claims they’ve made either on the Firefox security page or in some other public forum. As...
Microsoft Security Blog
Black Hat : Got2 Luv the H8ers
Posted
over 5 years ago
by
Jeff Jones - MSFT
24
Comments
So, this afternoon, I'm in the Microsoft booth at Black Hat when this guy comes up (badge hidden of course) and starts talking to some of my colleagues. Right away, it was pretty obvious that he was antagonistic. I will refer to him as "h8er" from here on out. Though I am paraphrasing a bit, this is based upon a true story. It gave me a chuckle, so I thought I'd share. h8er: So, how does it feel to work for a company that has made so many bad security decisions. MSFT guy: Well, I feel lucky to be...
Microsoft Security Blog
Download: Internet Explorer and Firefox Vulnerability Analysis
Posted
over 6 years ago
by
Jeff Jones - MSFT
24
Comments
Summary: For most people, their web browser is central to their interaction with the Internet, connecting to global web sites and helping them consume online services providing everything from booking flights to banking services to online shopping. This reality makes browsers a key tool when evaluating the security experience of users as the browser interprets Web content and programs delivered from around the world. Over the past few years, there has been much discussion of the need for improvements...
Microsoft Security Blog
July 2007 - Operating System Vulnerability Scorecard
Posted
over 6 years ago
by
Jeff Jones - MSFT
21
Comments
Summer and work travel have really had an impact and I've missed a couple of months of scorecards, so last weekend, I decided to dig in and catch up to July. I hit a few road bumps: Sun changed their Security Alerts web site, making it a bit more challenging. I gave up for now, but will try to add them back with subsequent scorecards. Novell, in a similar but different move, created a new psdb page for their version Enterprise Linux v10 SP1 products. At first, I thought they had not released any...
Microsoft Security Blog
Rise of Malicious Software and Increasing Privacy Concerns – TwC Interactive Timeline Part 2
Posted
over 1 year ago
by
Bruce Cowper - Microsoft
20
Comments
Continuing the Interactive Timeline series outlining some of the seminal events that have occurred over the last decade, this post looks at more of the key events that shaped the early Millennium, helping to create the perfect storm. Rise of Malicious Software In 1991, about 1,000 computer viruses existed worldwide. Malicious software became known to many computer users through the widespread infections caused by the email-based Melissa (1999) and ILOVEYOU (2000) viruses. By 2001, there were...
Microsoft Security Blog
Trustworthy Computing : Learning About Threats Over 10 Years–Part 5
Posted
over 1 year ago
by
Jeff Jones - MSFT
20
Comments
This post continue my analysis of industry vulnerability disclosures started in part 4 last week and is part of an ongoing series of posts based upon Tim Rains and my recent special edition Microsoft Security Intelligence Report (SIR) called “ The evolution of malware and the threat landscape – a ten year review, ” which we presented in a breakout session earlier this month at RSA Conference 2012. In the first three parts of this series ( part 1 , part 2 , part 3 ), Tim Rains explored some of the...
Microsoft Security Blog
Ubuntu CVE Tracker
Posted
over 3 years ago
by
Jeff Jones - MSFT
18
Comments
Today I was looking at some of the various vendor security and advisory sites and I noticed at the top of the Ubuntu site: For more details on a specific CVE or source package, please see the Ubuntu CVE Tracker . I had not seen the Ubuntu CVE Tracker before, so I checked out, very interested because of the fact that certain sites continue to assert and report that some Linux distributions do not have any Unpatched issues. For example, take a look at the page Vulnerability Report: Ubuntu...
Microsoft Security Blog
SQL Server - Fact Checking Recent Vulnerability History
Posted
over 5 years ago
by
Jeff Jones - MSFT
15
Comments
UPDATE: The story that originally got my attention has been updated in all of the places I could still find it yesterday, so I'm pulling my references to the story and just focusing on the positive story of SQL Security improvement. Jeff Last week a web-based news story comes to my attention which asserted that last year SQL Server had "... most vulnerabilities last year of any commercial database..." That prompted me to do some fact checking and I thought it worth documenting the real (really good...
Page 1 of 43 (430 items)
1
2
3
4
5
»