Microsoft.com Operations Team Blog
-
Microsoft Releases Security Advisory 2914486
Today we released Security Advisory 2914486 regarding a local elevation of privilege (EoP) issue that affects customers using Microsoft Windows XP and Server 2003. Windows Vista and later are not affected by this local EoP issue. A member of the Microsoft Active Protections Program (MAPP) found this issue being used on systems compromised by a third-party remote code execution vulnerability. These limited, targeted attacks require users to open a malicious PDF file. The issues described by the advisory cannot be used to gain access to a remote system alone.
-
Security and policy surrounding bring your own devices (BYOD)
As the proliferation of devices continues to capture the imagination of consumers, and has ignited what is referred to as bring your own device (BYOD) revolution, many IT departments across the globe are now facing increased security considerations. While organizations encourage BYOD for cost savings and productivity, it is also important to have robust security policies supporting BYOD.
-
Download Windows Server 2012 R2 and Get Free Training on the New Capabilities from MVA
As announced on the Windows Server blog last month, the team has released Windows Server 2012 R2 for General Availability. Download the Windows Server 2012 R2 evaluation or use our free Windows Server 2012 R2 Virtual Labs to test the product online without installation.Then, learn directly from Microsoft's product experts with a series of new Windows Server 2012 R2 courses on Microsoft Virtual Academy:View all of the latest courses on Windows Server 2012 on the MVA Windows Server Topic Page. -
Gobble gobble! 8 apps you need to make it through Thanksgiving!
-
Microsoft Cybersecurity Report: Top 10 Most Wanted Enterprise Threats
In my travels abroad over the years, I have had the great opportunity to meet with many enterprise customers to discuss the evolving threat landscape. In addition to helping inform customers, these meetings have provided me with an opportunity to learn more about how customers are managing risk within their environments. Many of these customers are interested in learning about the top threats found in enterprise environments. Visibility into what threats are most common in enterprise environments helps organizations assess their current security posture and better prioritize their security investments. Given the high level of interest in this information, I thought it would be helpful to take a close look at the top 10 threats facing enterprise customers based on new intelligence from the latest Microsoft Security Intelligence Report (SIRv15).
-
The R2 is available at Tech Showcase!
Windows Server 2012 R2 is available at Tech Showcase. The new R2 offers exciting features and enhancements across virtualization, storage, networking, virtual desktop infrastructure, access and information protection, and more. Attend a Microsoft Tech Showcase event and explore what R2 has to offer you and your organization. Register at http://aka.ms/Yclp43Tech Showcase events, hosted by Microsoft Learning Partners, are intended for senior technical experts and IT professional. Attend an event to review new, breakthrough features and capabilities important to you as an It Professional. Plan ahead and help you and your team get skilled and ready for the latest Windows release. -
Ransomware is on the Rise, Especially in Europe
The recently published Microsoft Security Intelligence Report (SIRv15) contains a section on ransomware. Ransomware is a type of malware that is designed to render a computer or its files unusable until the computer user pays the demanded amount of money to the attacker. It often masquerades as an official-looking warning from a well-known law enforcement agency, such as the US Federal Bureau of Investigation (FBI) or the Metropolitan Police Service of London. Some examples are provided in Figure 1.
-
MBSA 2.3 and the November 2013 Security Bulletin Webcast, Q&A, and Slide Deck
Today we’re publishing the November 2013 Security Bulletin Webcast Questions & Answers page. The majority of questions focused on the ActiveX Kill Bits bulletin (MS13-090) and the advisories. We also answered a few general questions that were not specific to any of this month’s updates, but that may be of interest.
-
EMET 4.1 Released
One of the tools I get asked most about when I’m with customers is the Enhanced Mitigations Experience Toolkit (EMET). EMET is a free mitigation tool designed to help IT Professionals and developers prevent vulnerabilities in software from being successfully exploited. The tool works by protecting applications via the latest security mitigation technologies built into Windows, even in cases where the developer of the application didn’t opt to do this themselves. By doing so, it enables a wide variety of software to be made significantly more resistant to exploitation – even against zero day vulnerabilities and vulnerabilities for which an update has not yet been applied.
-
The Threat Landscape in South America: Chile and Colombia
In this fourth and final part of our series on the threat landscape in South America, we examine threats in Chile and then Colombia. As illustrated in Figure 1, both of these regions have had periods where their malware infection rates were above the worldwide average, and have more recently trended down. Read more