Microsoft

Microsoft releases four security patches, one critical

November 08, 2011

Microsoft on Tuesday patched one "critical" vulnerability, plus three other less-severe flaws. Not patched, as expected, is a bug related to the Duqu trojan.
 

Microsoft issues workaround for Duqu malware

November 04, 2011

Microsoft issued a temporary fix for a vulnerability in the Windows kernel used to spread Duqu, the so-called "son of Stuxnet" trojan.
 

Microsoft security update addresses four flaws, not Duqu

November 03, 2011

Microsoft is prepping four security bulletins for its November update, though it is not expected to provide a fix for the zero-day flaw used to spread Duqu.
 

Microsoft's October update to fix 23 flaws

October 06, 2011

The Patch Tuesday bulletins, of which two are rated "critical" and six deemed "important," are due Oct. 11 at about 2 p.m. EST.
 

Microsoft Windows 8 will ship with built-in anti-virus

September 14, 2011

Microsoft may face challenges from anti-virus rivals after announcing this week that the next version of Windows will come with built-in AV protection.
 

Microsoft, Adobe release scheduled security patches

September 13, 2011

Microsoft released five important bulletins addressing 15 flaws, along with an update revoking six more DigiNotar certificates, while Adobe issued critical updates for Reader and Acrobat.
 

Microsoft Patch Tuesday fixes 22 vulnerabilities

August 09, 2011

As part of its monthly Patch Tuesday upgrades, Microsoft on Tuesday released fixes for 22 vulnerabilities discovered in Internet Explorer, Windows, Visio and Visual Studio.
 

Microsoft distributes Windows, PowerPoint patches

May 10, 2011

Microsoft on Tuesday delivered two patches to address three vulnerabilities, but because of default settings, built-in protections and unaffected newer versions, experts don't anticipate widespread attacks ensuing.
 

Microsoft readying fixes for Windows, Office flaws

May 05, 2011

Following a record-breaking security update last month, Microsoft is planning just two fixes for its June update, plus a revamped exploitability index.
 

Microsoft's April patch batch to address 64 flaws

April 07, 2011

Microsoft's planned security update for next week likely will include a fix for a vulnerability that is being actively exploited.
 

Adobe advises of Flash flaw exploited via Excel docs

March 14, 2011

Adobe on Monday warned of a "critical" zero-day vulnerability in Flash Player that attackers currently are exploiting through Microsoft Excel files.
 

Microsoft says zero-day flaw not exploitable remotely

February 18, 2011

Microsoft confirmed the existence of an unpatched vulnerability affecting all versions of Windows, but said it is unlikely the flaw could be exploited remotely.
 

Microsoft kicks off 2011 with light patch load

January 11, 2011

Tuesday's security update is comprised of two fixes for three vulnerabilities, but it does not address two publicly known flaws.
 

Microsoft adds Zeus detection, removal to tool

October 12, 2010

Microsoft on Tuesday announced that it has added new protection capabilities to its Malicious Software Removal Tool to help organizations fight the insidious data-stealing malware Zeus. The removal tool, released Tuesday as part of Microsoft's monthly security update, detects and cleans the malware. Microsoft researchers said Tuesday in blog post that Zeus, also known as Zbot, is "quite complex and varied" but distributing it does not take much technical sophistication since toolkits to create the malware are easily obtainable on underground forums. The new detection capability comes in the wake of a series of attests disrupting an international cybercrime operation linked to Zeus.— AM
 

Black Hat 2010: Like Safari, Internet Explorer 6 and 7 suffer from auto-fill flaw

July 29, 2010

Internet Explorer suffers from a similar auto-fill feature that Apple is grappling with, a well-known web researcher said Thursday at the Black Hat conference in Las Vegas.
 

Stuxnet malware threat continues, targets control systems

July 21, 2010

Microsoft has issued a new "Fix It" temporary remedy for a Windows vulnerability that is permitting targeted malware to spread via removable media.
 

Microsoft issues 10 patches as part of June update

June 08, 2010

Microsoft on Tuesday pushed out 10 patches to address a whopping 34 vulnerabilities as part of its June security update.
 

Report: Google to discontinue Windows use for workers

June 01, 2010

Google is planning to migrate its end-users away from the use of Windows in the wake of Chinese-led targeted attacks that raided its corporate infrastructure of intellectual property, a Monday report in the Financial Times said.
 

Two severe bugs silently fixed in recent Microsoft update

May 06, 2010

A recent Microsoft security patch silently fixed two severe vulnerabilities that were not disclosed, leading to criticism that the software giant downplayed the severity of the patch.
 

Microsoft Office name being used to compromise PCs

January 08, 2010

The Microsoft Office name is being leveraged by cybercriminals in two new campaigns meant to infect users' machines. Email security firm Red Condor on Thursday warned of a spear phishing run in which messages appear to be invitations for recipients to update their Microsoft Office Outlook Web Access settings. Following the link, however, leads to the pernicious, data-stealing Zeus trojan. In another scam, searches for "office.microsoft.com" is leading to malicious websites hawking rogue anti-virus programs, internet security vendor Websense said Friday in a blog post. — DK
 

Experts optimistic about the security of Windows 7

October 21, 2009

Windows 7 builds on the security of the Vista operating system, including a refashioned way to control administrator access.
 

Microsoft sues five companies over malware-laden ads

September 18, 2009

Microsoft is back in the courts, this time suing alleged purveyors of malicious advertisements.
 

Microsoft leads browsers in malware, phishing defense

August 14, 2009

Surprised? Microsoft came out on top in a recent test that studied how well the leading web browsers respond to malware and phishing.
 

Microsoft pushes out ATL, ActiveX fixes

August 11, 2009

The software giant on Tuesday cleaned up its flawed Active Template Library, in addition to issuing a host of other patches.
 

Group of ISPs issue tips for dealing with bots

August 07, 2009

One industry group is trying to help network operators help respond to bot infections.
 

Emergency patches issued for IE and Visual Studio

July 28, 2009

Microsoft on Tuesday issued two out-of-band security patches -- one for the development tools suite Visual Studio and another for Internet Explorer.
 

Microsoft set to deliver two emergency updates Tuesday

July 25, 2009

In an unusual move, Microsoft late Friday announced that it plans to release two out-of-band security patches next week to address an underlying issue in Windows.
 

Microsoft distributes six patches for nine vulnerabilities

July 14, 2009

Microsoft plugged two zero-day exploits, along with a number of other vulnerabilities, as part of its monthly patch cycle on Tuesday.
 

Another ActiveX zero-day bug from Microsoft

July 13, 2009

Microsoft is trying to combat another ActiveX vulnerability being actively exploited -- the second in a week.
 

DirectShow, ActiveX 0-days among planned Microsoft fixes

July 09, 2009

Microsoft is hoping it can pull off a quick turnaround for a fix of a zero-day ActiveX vulnerability that was only disclosed this week.