Sans News Feed
- ISC Stormcast For Thursday, February 13th, 2025 https://isc.sans.edu/podcastdetail/9322, (Thu, Feb 13th) February 13, 2025
- DShield SIEM Docker Updates, (Thu, Feb 13th) February 13, 2025Over the past several weeks, I have been testing various enhancements to the DShield SIEM, to process DShield sensor log from local and cloud sensors with Filebeat and Filebeat modules to easily send Zeek and NetFlow logs back to a local network ELK stack via home router natting. This is a list of updates and […]
- An ontology for threats, cybercrime and digital forensic investigation on Smart City Infrastructure, (Wed, Feb 12th) February 12, 2025Blue teams have it hard â they maintain a watchful eye on whatever technology is deployed to detect threats, respond to incidents, perform digital forensics and reverse malware (or make malware happy!) when needed. Hopefully, no one has to handle all these roles alone since there is also the continuous learning aspect of getting up […]
- ISC Stormcast For Wednesday, February 12th, 2025 https://isc.sans.edu/podcastdetail/9320, (Wed, Feb 12th) February 12, 2025
- Microsoft February 2025 Patch Tuesday, (Tue, Feb 11th) February 11, 2025This month, Microsoft has released patches addressing a total of 141 vulnerabilities. Among these, 4 are classified as critical, highlighting the potential for significant impact if exploited. Notably, 2 vulnerabilities are currently being exploited in the wild, underscoring the urgency for immediate updates. Additionally, 1 vulnerability has been disclosed prior to this patch cycle, marking […]
- ISC Stormcast For Tuesday, February 11th, 2025 https://isc.sans.edu/podcastdetail/9318, (Tue, Feb 11th) February 11, 2025
- 
Reminder: 7-Zip & MoW, (Mon, Feb 10th) February 10, 2025CVE-2025-0411 is a vulnerability in 7-zip that has been reported to be exploited in recent attacks. The problem is that Mark-of-Web (MoW) isn't propagated correctly: when extracted, a file inside a ZIP file inside another ZIP file will not have the MoW propagated from the outer ZIP file.
- ISC Stormcast For Monday, February 10th, 2025 https://isc.sans.edu/podcastdetail/9316, (Mon, Feb 10th) February 10, 2025
- Crypto Wallet Scam: Not For Free, (Sat, Feb 8th) February 8, 2025I did some research into multisig wallets (cfr "Crypto Wallet Scam"), and discovered that setting up such a wallet on the TRON network comes with a cost: about $23.
- SSL 2.0 turns 30 this Sunday... Perhaps the time has come to let it die?, (Fri, Feb 7th) February 7, 2025The SSL 2.0 protocol was originally published back in February of 1995[1], and although it was quickly found to have significant security weaknesses, and a more secure alternative was released only a year later[2], it still received a fairly wide adoption.
Microsoft Security Feed
- Exciting updates to the Copilot (AI) Bounty Program: Enhancing security and incentivizing innovation February 7, 2025At Microsoft, we are committed to fostering a secure and innovative environment for our customers and users. As part of this commitment, we are thrilled to announce significant updates to our Copilot (AI) Bounty Program. These changes are designed to enhance the program’s effectiveness, incentivize broader participation, and ensure that our Copilot consumer products remain […]
- Scaling Dynamic Application Security Testing (DAST) January 21, 2025Introduction Microsoft engineering teams use the Security Development Lifecycle to ensure our products are built in alignment with Microsoft’s Secure Future Initiative security principles: Secure by Design, Secure by Default, and Secure Operations. A key component of the Security Development Lifecycle is security testing, which aims to discover and mitigate security vulnerabilities before adversaries can […]
- Congratulations to the Top MSRC 2024 Q4 Security Researchers! January 15, 2025Congratulations to all the researchers recognized in this quarter’s Microsoft Researcher Recognition Program leaderboard! Thank you to everyone for your hard work and continued partnership to secure customers. The top three researchers of the 2024 Q4 Security Researcher Leaderboard are Suresh, VictorV, wkai! Check out the full list of researchers recognized this quarter here.
- Mitigating NTLM Relay Attacks by Default December 9, 2024Introduction In February 2024, we released an update to Exchange Server which contained a security improvement referenced by CVE-2024-21410 that enabled Extended Protection for Authentication (EPA) by default for new and existing installs of Exchange 2019. While we’re currently unaware of any active threat campaigns involving NTLM relaying attacks against Exchange, we have observed threat […]
- Announcing the Adaptive Prompt Injection Challenge (LLMail-Inject) December 6, 2024We are excited to introduce LLMail-Inject, a new challenge focused on evaluating state-of-the-art prompt injection defenses in a realistic simulated LLM-integrated email client. In this challenge, participants assume the role of an attacker who sends an email to a user. The user then queries the LLMail service with a question (e.
- Securing AI and Cloud with the Zero Day Quest November 19, 2024Our security teams work around the clock to help protect every person and organization on the planet from security threats. We also know that security is a team sport, and that’s why we also partner with the global security community through our bug bounty programs to proactively identify and mitigate potential issues before our customers […]
- Toward greater transparency: Publishing machine-readable CSAF files November 12, 2024Welcome to the third installment in our series on transparency at the Microsoft Security Response Center (MSRC). In this ongoing discussion, we talk about our commitment to providing comprehensive vulnerability information to our customers. At MSRC, our mission is to protect our customers, communities, and Microsoft, from current and emerging threats to security and privacy.
- Congratulations to the Top MSRC 2024 Q3 Security Researchers! October 23, 2024Congratulations to all the researchers recognized in this quarter’s Microsoft Researcher Recognition Program leaderboard! Thank you to everyone for your hard work and continued partnership to secure customers. The top three researchers of the 2024 Q3 Security Researcher Leaderboard are wkai, VictorV, and Zhihua Wen! Check out the full list of researchers recognized this quarter […]
- Announcing the BlueHat 2024 Sessions October 22, 202434 sessions from 54 presenters representing 20 organizations! We are thrilled to reveal the lineup of speakers and presentations for the 23rd BlueHat Security Conference, in Redmond WA from Oct 29-30. This year’s conference continues the BlueHat ethos and Secure Future Initiative mission of “Security Above All Else”. Security researchers and responders from inside and outside […]
- Announcing BlueHat 2024: Call for Papers now open August 7, 2024The 23rd edition of Microsoft’s BlueHat security conference will be hosted by the Microsoft Security Response Center (MSRC) at the Redmond, WA corporate campus, October 29 and 30, 2024. BlueHat brings together security researchers and responders from both inside and outside of Microsoft, who come together as peers to exchange ideas, experiences, and best practices, all […]
Cyber Security Alerts
- CISA Calls For Action to Close the Software Understanding Gap January 16, 2025 CISA
- CISA Publishes Microsoft Expanded Cloud Log Implementation Playbook January 15, 2025 CISA
- CISA, JCDC, Government and Industry Partners Publish AI Cybersecurity Collaboration Playbook January 14, 2025 CISA
- CISA Releases New Sector Specific Goals for IT and Product Design January 7, 2025 CISA
- CISA Update on Treasury Breach January 6, 2025 CISA
- CISA Directs Federal Agencies to Secure Cloud Environments December 17, 2024 CISA
- CISA and ONCD Publish Guide to Strengthen Cybersecurity of Grant-Funded Infrastructure Projects December 17, 2024 CISA
- CISA Publishes Draft National Cyber Incident Response Plan for Public Comment December 16, 2024 CISA
- 2024 Year in Review Highlights CISA’s Achievements in Reducing Risk and Building Resilience in Cybersecurity and Critical Infrastructure Security December 16, 2024 CISA
- CISA, NSA, FBI and International Partners Publish Guide for Protecting Communications Infrastructure December 3, 2024 CISA