Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Recent content on Microsoft Security Response Center
Updated: 57 min 31 sec ago

Exciting updates to the Copilot (AI) Bounty Program: Enhancing security and incentivizing innovation

Fri, 02/07/2025 - 08:00
At Microsoft, we are committed to fostering a secure and innovative environment for our customers and users. As part of this commitment, we are thrilled to announce significant updates to our Copilot (AI) Bounty Program. These changes are designed to enhance the program’s effectiveness, incentivize broader participation, and ensure that our Copilot consumer products remain robust, safe, and secure.
Categories: Microsoft

Scaling Dynamic Application Security Testing (DAST)

Tue, 01/21/2025 - 08:00
Table of Contents Introduction Why most enterprises have trouble scaling DAST Web endpoint discovery Automated OpenAPI Specification generation solutions that do scale (sort of) Authentication and authorization A scalable DAST solution Web endpoint discovery Authentication and authorization Authentication hook Authorization hook DAST orchestration platform architecture Conclusion and looking ahead Introduction Microsoft engineering teams use the Security Development Lifecycle to ensure our products are built in alignment with Microsoft’s Secure Future Initiative security principles: Secure by Design, Secure by Default, and Secure Operations.
Categories: Microsoft

Congratulations to the Top MSRC 2024 Q4 Security Researchers!

Wed, 01/15/2025 - 08:00
Congratulations to all the researchers recognized in this quarter’s Microsoft Researcher Recognition Program leaderboard! Thank you to everyone for your hard work and continued partnership to secure customers. The top three researchers of the 2024 Q4 Security Researcher Leaderboard are Suresh, VictorV, wkai! Check out the full list of researchers recognized this quarter here.
Categories: Microsoft

Mitigating NTLM Relay Attacks by Default

Mon, 12/09/2024 - 08:00
Introduction In February 2024, we released an update to Exchange Server which contained a security improvement referenced by CVE-2024-21410 that enabled Extended Protection for Authentication (EPA) by default for new and existing installs of Exchange 2019. While we’re currently unaware of any active threat campaigns involving NTLM relaying attacks against Exchange, we have observed threat actors exploiting this vector in the past.
Categories: Microsoft

Announcing the Adaptive Prompt Injection Challenge (LLMail-Inject)

Fri, 12/06/2024 - 08:00
We are excited to introduce LLMail-Inject, a new challenge focused on evaluating state-of-the-art prompt injection defenses in a realistic simulated LLM-integrated email client. In this challenge, participants assume the role of an attacker who sends an email to a user. The user then queries the LLMail service with a question (e.
Categories: Microsoft

Securing AI and Cloud with the Zero Day Quest

Tue, 11/19/2024 - 08:00
Our security teams work around the clock to help protect every person and organization on the planet from security threats. We also know that security is a team sport, and that’s why we also partner with the global security community through our bug bounty programs to proactively identify and mitigate potential issues before our customers are impacted.
Categories: Microsoft

Toward greater transparency: Publishing machine-readable CSAF files

Tue, 11/12/2024 - 08:00
Welcome to the third installment in our series on transparency at the Microsoft Security Response Center (MSRC). In this ongoing discussion, we talk about our commitment to providing comprehensive vulnerability information to our customers. At MSRC, our mission is to protect our customers, communities, and Microsoft, from current and emerging threats to security and privacy.
Categories: Microsoft