See product news and on-demand sessions from Microsoft Secure

Credit to Author: Christine Barrett| Date: Mon, 17 Apr 2023 16:00:00 +0000

Microsoft Secure on March 28, 2023, was a major success, thanks to more than 51,000 virtual attendees. It’s not too late to watch a session you missed. Watch on-demand.

The post See product news and on-demand sessions from Microsoft Secure appeared first on Microsoft Security Blog.

Read more

Threat actors strive to cause Tax Day headaches

Credit to Author: Microsoft Security Threat Intelligence – Editor| Date: Thu, 13 Apr 2023 17:00:00 +0000

With U.S. Tax Day approaching, Microsoft has observed phishing attacks targeting accounting and tax return preparation firms to deliver the Remcos RAT and compromise target networks.

The post Threat actors strive to cause Tax Day headaches appeared first on Microsoft Security Blog.

Read more

Improve supply chain security and resiliency with Microsoft  

Credit to Author: Christine Barrett| Date: Thu, 13 Apr 2023 15:00:00 +0000

The Microsoft Supply Chain Platform was just launched to help companies protect their supply chains against cyber threats.

The post Improve supply chain security and resiliency with Microsoft   appeared first on Microsoft Security Blog.

Read more

LinkedIn and Microsoft Entra introduce a new way to verify your workplace

Credit to Author: Christine Barrett| Date: Wed, 12 Apr 2023 13:00:00 +0000

LinkedIn members can use a Microsoft Entra Verified ID credential issued from their organization to verify their workplace on their public profile and add instant credibility, increasing trust and confidence in interactions.

The post LinkedIn and Microsoft Entra introduce a new way to verify your workplace appeared first on Microsoft Security Blog.

Read more

Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign

Credit to Author: Microsoft Security Threat Intelligence – Editor| Date: Tue, 11 Apr 2023 17:00:00 +0000

This guide provides steps that organizations can take to assess whether users have been targeted or compromised by threat actors exploiting CVE-2022-21894 via a Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus.

The post Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign appeared first on Microsoft Security Blog.

Read more

DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia

Credit to Author: Microsoft Security Threat Intelligence| Date: Tue, 11 Apr 2023 16:00:00 +0000

Microsoft analyzes a threat group tracked as DEV-0196, the actor’s iOS malware “KingsPawn”, and their link to an Israel-based private sector offensive actor (PSOA) known as QuaDream, which reportedly sells a suite of exploits, malware, and infrastructure called REIGN, that’s designed to exfiltrate data from mobile devices.

The post DEV-0196: QuaDream’s “KingsPawn” malware used to target civil society in Europe, North America, the Middle East, and Southeast Asia appeared first on Microsoft Security Blog.

Read more

MERCURY and DEV-1084: Destructive attack on hybrid environment

Credit to Author: Microsoft Security Threat Intelligence| Date: Fri, 07 Apr 2023 16:00:00 +0000

Microsoft detected a unique operation where threat actors carried out destructive actions in both on-premises and cloud environments.

The post MERCURY and DEV-1084: Destructive attack on hybrid environment appeared first on Microsoft Security Blog.

Read more

DevOps threat matrix

Credit to Author: Microsoft Security Threat Intelligence| Date: Thu, 06 Apr 2023 17:00:00 +0000

In this blog, we discuss threats we face in our DevOps environment, introducing our new threat matrix for DevOps. Using this matrix, we show the different techniques an adversary might use to attack an organization from the initial access phase and forward.

The post DevOps threat matrix appeared first on Microsoft Security Blog.

Read more

Discover a new era of security with Microsoft at RSAC 2023

Credit to Author: Christine Barrett| Date: Tue, 04 Apr 2023 16:00:00 +0000

Microsoft Security will be at the 2023 RSA Conference and we’d love to connect with you there. In this blog post, we share all the ways you can—plus, attend the Pre-Day with Microsoft and watch the Microsoft Security Copilot demo.

The post Discover a new era of security with Microsoft at RSAC 2023 appeared first on Microsoft Security Blog.

Read more