Skip to main content

Microsoft

Microsoft: 70 Percent of All Security Bugs Are Memory Safety Issues

posted onFebruary 11, 2019
by l33tdawg
Credit: ZDNet

Around 70 percent of all the vulnerabilities in Microsoft products addressed through a security update each year are memory safety issues; a Microsoft engineer revealed last week at a security conference.

Memory safety is a term used by software and security engineers to describe applications that access the operating system's memory in a way that doesn't cause errors. Memory safety bugs happen when software, accidentally or intentionally, accesses system memory in a way that exceeds its allocated size and memory addresses.

Windows 7 Extended Security Updates will double in price each year

posted onFebruary 6, 2019
by l33tdawg
Credit: Wikipedia

Windows 7's free support period ends on January 14, 2020. Microsoft is offering three years of support updates for the operating system on a paid basis with a new program called Extended Security Updates (ESU). Unlike previous after-life support options for Windows, which were offered as part of separately negotiated support contracts, the Windows 7 ESU updates will be available to any volume license customer, regardless of size or sales channel.

Microsoft Confirms Windows Update Problems Were Caused by DNS Issues

posted onFebruary 5, 2019
by l33tdawg
Credit: Bleeping Computer

Since January 29th, Windows 10 users have been reporting problems connecting to Windows Update. Microsoft has confirmed that this was caused by DNS corruption at an external DNS provider that was causing bad records to be pushed to ISP's DNS servers.

Just yesterday we reported that even though Microsoft had reportedly fixed the issue, users were still complaining that they were unable to connect to Windows Update. At the time of that article's writing, Microsoft had still not disclosed any information regarding the cause of the problems.

Phishers Use Zero-Width Spaces to Bypass Office 365 Protections

posted onJanuary 11, 2019
by l33tdawg
Credit: Wikipedia

A recently addressed vulnerability in Office 365 allowed attackers to bypass existing phishing protections and deliver malicious messages to victims’ inboxes.

The issue, cloud security firm Avanan says, resided in the use of zero-width spaces (ZWSPs) in the middle of malicious URLs within the RAW HTML of the emails. This method breaks the URLs, thus preventing Microsoft’s systems from recognizing them and also preventing Safe Links from successfully protecting users.

New Windows 10 build silences Cortana, brings passwordless accounts

posted onJanuary 4, 2019
by l33tdawg
Credit: Arstechnica

The latest Insider build of Windows 10, 18309, expands the use of a thing that Microsoft has recently introduced: passwordless Microsoft accounts. It's now possible to create a Microsoft account that uses a one-time code delivered over SMS as its primary authenticator, rather than a conventional password.

Microsoft adds Dark Mode support and more to Office 365 for Mac

posted onDecember 13, 2018
by l33tdawg
Credit: Arstechnica

Microsoft has released version 16.20.18120801 of Office 365 for the Mac platform, bringing support for a couple of key Mac features introduced in September's macOS 10.14 Mojave release, as well as a number of small features and user experience improvements not related to Mojave.