Jump to content
Microsoft Windows Bulletin Board

Windows Security

Active Members
  • Posts

    1215
  • Joined

  • Last visited

    Never

Everything posted by Windows Security

  1. Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.View the full article
  2. Information published.View the full article
  3. Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.View the full article
  4. Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.View the full article
  5. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.View the full article
  6. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.View the full article
  7. Information published.View the full article
  8. Table of Contents Introduction Why most enterprises have trouble scaling DAST Web endpoint discovery Automated OpenAPI Specification generation solutions that do scale (sort of) Authentication and authorization A scalable DAST solution Web endpoint discovery Authentication and authorization Authentication hook Authorization hook DAST orchestration platform architecture Conclusion and looking ahead Introduction Microsoft engineering teams use the Security Development Lifecycle to ensure our products are built in alignment with Microsoft’s Secure Future Initiative security principles: Secure by Design, Secure by Default, and Secure Operations.View the full article
  9. Congratulations to all the researchers recognized in this quarter’s Microsoft Researcher Recognition Program leaderboard! Thank you to everyone for your hard work and continued partnership to secure customers. The top three researchers of the 2024 Q4 Security Researcher Leaderboard are Suresh, VictorV, wkai! Check out the full list of researchers recognized this quarter here.View the full article
  10. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025 ) for more information.View the full article
  11. The following updates have been made: 1) Added Windows Software to the Security Updates table. Microsoft recommends updating to the latest version of their Windows operating system. 2) Added an FAQ to describe further actions customers need to take to be protected from this vulnerability.View the full article
  12. Information published.View the full article
  13. Information published.View the full article
  14. Information published.View the full article
  15. Information published.View the full article
  16. Information published.View the full article
  17. Information published.View the full article
  18. Information published.View the full article
  19. Information published.View the full article
  20. Information published.View the full article
×
×
  • Create New...