Skip to main content
MSRC

msrc

Thoughts on Steve Ballmer's keynote

Monday, June 06, 2005

Wow, oh wow. It’s always a pleasure to see Steve Ballmer speak, and it’s a greater privilege to be here at Tech Ed 2005 supporting the great things he noted in his keynote. I’ve seen Bill Gates speak many times, but other than some internal presentations to employees I’ve never gotten a chance to see Steve speak to our customers live.

MSRC focus group at TechEd -- tell us what you think!

Tuesday, May 24, 2005

Hi folks, counting down - it’s just a couple of weeks now until TechEd Orlando. Stephen, Mike and I are excited to have the opportunity once again to meet our customers, and hear your experiences and feedback around our security bulletins. This year at TechEd we will take this a step further with a focus group on exactly this topic.

Is there a new MSN Messenger update or not?

Friday, May 20, 2005

Hey folks - Mike Reavey here. Recently, some folks have asked us if there’s a new security update in MSN Messenger. In doing some investigation, we’ve realized that these questions might be coming in because the “Date Published” on this page on our Download Center: shows it was published last Tuesday.

Sasser Worm Anniversary & MSRC Learnings

Friday, May 20, 2005

It’s been just over a year since we experienced our last major network worm outbreak, Sasser, which exploited a vulnerability in the LSASS component of Windows in April 2004. On the security response team at Microsoft, it is part of our process to do post mortems after incidents or outbreaks and review how we can better manage these incidents more effectively for customers.

Customers Help Us Improve Security Communications

Tuesday, May 10, 2005

Debby Fry Wilson here! I had the opportunity to attend the CanSecWest security research conference in Vancouver, Canada last week. It was a tremendously valuable and eye-opening experience to see and hear the passion, dedication and commitment that segments of security researchers put into their craft of finding and exposing security vulnerabilities in software products.

One security bulletin for May and a few more things...

Tuesday, May 10, 2005

Hi everyone, Mike Reavey here to tell you about today’s security bulletin and some other offerings to help protect and provide guidance for customers. Today’s release includes one bulletin affecting Windows 2000. It’s rated as “Important”. (This update addresses the recently disclosed “greymagic” vulnerability that Stephen blogged about a few weeks back.

Information on Publicly Disclosed Windows Vulnerability

Wednesday, April 20, 2005

Stephen Toulouse here with the MSRC, just wanted to provide everyone with some information related to public reports of a possible vulnerability in Microsoft Windows that was publicly disclosed. The issue involves the Windows Shell, and our initial investigation has found that significant user interaction would be required for an attacker to exploit this vulnerability.

Welcome to our new home.... and April Security Updates.

Tuesday, April 12, 2005

Hey everyone, this is Mike Reavey from the MSRC. Welcome to the Microsoft Security Response Center Blog’s new home! We here at the MSRC started the blog for our time at RSA 2005, but we had such great support and positive responses from customers that we’ve have decided to keep it going.

A little bit about the Security Update Validation Program

Tuesday, March 15, 2005

A little bit about the Security Update Validation Program Late last week there was some confusion about the Security Update Validation program, and I wanted to take a minute to explain how the program works and our reasons behind implementing it. To start, the Security Update Validation Program (SUVP) was tested for about a year before we officially announced it in January.

And introducing....

Tuesday, March 08, 2005

And introducing…. I’m Mike Reavey the Operations Lead for the Microsoft Security Response Center. I wanted to take a second to introduce myself and what my team does within the MSRC. Have you ever wondered who’s watching secure@microsoft.com around the clock to respond to new vulnerabilities? Or who works with the security researchers, product teams, and external partners to ensure a security update is complete and delivered to our customers?