Dasha Zenkovich, Author at Microsoft Security Blog http://approjects.co.za/?big=en-us/security/blog Expert coverage of cybersecurity topics Thu, 14 Nov 2024 18:59:27 +0000 en-US hourly 1 https://wordpress.org/?v=6.6.2 Microsoft Ignite: Sessions and demos to improve your security strategy http://approjects.co.za/?big=en-us/security/blog/2024/10/30/microsoft-ignite-sessions-and-demos-to-improve-your-security-strategy/ Wed, 30 Oct 2024 16:00:00 +0000 Join us at Microsoft Ignite 2024 for sessions, keynotes, and networking aimed at giving you tools and strategies to put security first in your organization.

The post Microsoft Ignite: Sessions and demos to improve your security strategy appeared first on Microsoft Security Blog.

]]>
Now more than ever is the time for every organization to prioritize security. The use of AI by cyberattackers gives them an asymmetric advantage over defenders, as cyberattackers only have to be right once, while defenders have to be right 100% of the time. The way to win is with AI-first, end-to-end security—a key focus for Microsoft Security at Microsoft Ignite, November 18 to 22, 2024. Join thousands of security professionals at the event online to become part of a community focused on advancing defenders against ever-evolving cyberthreats.

Across many sessions and demos, we’ll address the top security pain points related to AI and empower you with practical, actionable strategies. Keep reading this blog for a guide of highlighted sessions for security professionals of all levels, whether you’re attending in-person or online.

And be sure to register for the digital experience to explore the Microsoft Security sessions at Microsoft Ignite.

Be among the first to hear top news

Microsoft is bringing together every part of the company in a collective mission to advance cybersecurity protection to help our customers and the security community. We have four powerful advantages to drive security innovation: large-scale data and threat intelligence; end-to-end protection; responsible AI; and tools to secure and govern the use of AI.

Microsoft Chairman and Chief Executive Officer Satya Nadella said in May 2024 that security is the top priority for our company. At the Microsoft Ignite opening keynote on Tuesday, November 19, 2024, Microsoft Security Executive Vice President Charlie Bell and Corporate Vice President (CVP), Microsoft Security Business Vasu Jakkal will join Nadella to discuss Microsoft’s vision for the future of security. Other well-known cybersecurity speakers at Microsoft Ignite include Ann Johnson, CVP and Deputy Chief Information Security Officer (CISO); Joy Chik, President, Identity, and Network Access; Mark Russinovich, Chief Technology Officer and Deputy CISO; and Sherrod DeGrippo, Director of Threat Intelligence Strategy.

For a deeper dive into security product news and demos, join the security general session on Wednesday, November 20, 2024, at 11:00 AM CT. Hear from Vasu Jakkal; Joy Chik; Rob Lefferts, CVP, Microsoft Threat Protection; Herain Oberoi, General Manager, Microsoft Data Security, Privacy, and Compliance; and Michael Wallent, CVP; who will share exciting security innovations to empower you with AI tools designed to help you get ahead of attackers.

These news-breaking sessions are just the start of the value you can gain from attending online.

Benefit from insights designed for your role

While cybersecurity is a shared concern of security professionals, we realize the specific concerns are unique to role. Recognizing this, we developed sessions tailored to what matters most to you.

  • CISOs and senior security leaders: If you’ll be with us in Chicago, kick off the conference with the Microsoft Ignite Security Forum on November 18, 2024 from 1 PM CT to 5 PM CT. Join this exclusive pre-day event to hear from Microsoft security experts on threat intelligence insights, our Secure Future Initiative (SFI), and trends in security. Go back to your registration to add this experience on. Also for those in Chicago, be sure to join the Security Leaders Dinner, where you can engage with your peers and provide insights on your greatest challenges and successes. If you’re joining online, gain firsthand access to the latest Microsoft Security announcements. Whether you’re in person or online, don’t miss “Proactive security with continuous exposure management” (BRK324), which will explore how Microsoft Security Exposure Management unifies disparate data silos for visibility of end-to-end attack surface, and “Secure and govern data in Microsoft 365 Copilot and beyond” (BRK321), which will discuss the top concerns of security leaders when it comes to AI and how you can gain the confidence and tools to adopt AI. Plus, learn how to make your organization as diverse as the threats you are defending in “The Power of Diversity: Building a stronger workforce in the era of AI” (BRK330).
  • Security analysts and engineers: Join actionable sessions for information you can use immediately. Sessions designed for the security operations center (SOC) include “Microsoft cybersecurity architect lab—Infrastructure security” (LAB454), which will showcase how to best use the Microsoft Secure Score to improve your security posture, and “Simplify your SOC with the unified security operations platform” (BRK310), which will feature a fireside chat with security experts to discuss common security challenges and topics. Plus, learn to be a champion of safe AI adoption in “Scott and Mark learn responsible AI” (BRK329), which will explore the three top risks in large language models and the origins and potential impacts of each of these.
  • Developers and IT professionals: We get it—security isn’t your main focus, but it’s increasingly becoming part of your scope. Get answers to your most pressing questions at Microsoft Ignite. Sessions that may interest you include “Secure and govern custom AI built on Azure AI and Copilot Studio” (BRK322), which will dive into how Microsoft can enable data security and compliance controls for custom apps, detect and respond to AI threats, and managed your AI stack vulnerabilities, and “Making Zero Trust real: Top 10 security controls you can implement now” (BRK328), which offers technical guidance to make Zero Trust actionable with 10 top controls to help improve your organization’s security posture. Plus, join “Supercharge endpoint management with Microsoft Copilot in Intune” (THR656) for guidance on unlocking Microsoft Intune’s potential to streamline endpoint management.
  • Microsoft partners: We appreciate our partners and have developed sessions aimed at supporting you. These include “Security partner growth: The power of identity with Entra Suite” (BRK332) and “Security partner growth: Help customers modernize security operations” (BRK336).

Attend sessions tailored to addressing your top challenge

When exploring effective cybersecurity strategies, you likely have specific challenges that are motivating your actions, regardless of your role within your organization. We respect that our attendees want a Microsoft Ignite experience tailored to their specific objectives. We’re committed to maximizing your value from attending the event, with Microsoft Security sessions that address the most common cybersecurity challenges.

  • Managing complexity: Discover ways to simplify your infrastructure in sessions like “Simpler, smarter, and more secure endpoint management with Intune” (BRK319), which will explore new ways to strengthen your security with Microsoft Intune and AI, and “Break down risk silos and build up code-to-code security posture” (BRK312), which will focus on how defenders can overcome the expansive alphabet soup of security posture tools and gain a unified cloud security posture with Microsoft Defender for Cloud.   
  • Increasing efficiency:: Learn how AI can help you overcome talent shortage challenges in sessions like “Secure data across its lifecycle in the era of AI” (BRK318), which will explore Microsoft Purview leveraging Microsoft Security Copilot can help you detect hidden risks, mitigate them, and protect and prevent data loss, and “One goal, many roles: Microsoft Security Copilot: Real-world insights and expert advice” (BRK316), which will share best practices and insider tricks to maximize Copilot’s benefits so you can realize quick value and enhance your security and IT operations.  
  • Threat landscape: Navigate effectively through the modern cyberthreat landscape, guided by the insights shared in sessions like “AI-driven ransomware protection at machine speed: Defender for Endpoint” (BRK325), which will share a secret in Microsoft Defender for Endpoint success and how it uses machine learning and threat intelligence, and the theater session “Threat intelligence at machine speed with Microsoft Security Copilot” (THR555), which will showcase how Copilot can be used as a research assistant, analyst, and responder to simplify threat management.
  • Regulatory compliance: Increase your confidence in meeting regulatory requirements by attending sessions like “Secure and govern your data estate with Microsoft Purview” (BRK317), which will explore how to secure and govern your data with Microsoft Purview, and “Secure and govern your data with Microsoft Fabric and Purview” (BRK327), which will dive into how Microsoft Purview works together with Microsoft Fabric for a comprehensive approach to secure and govern data.
  • Maximizing value: Discover how to maximize the value of your cybersecurity investments during sessions like “Transform your security with GenAI innovations in Security Copilot” (BRK307), which will showcase how Microsoft Security Copilot’s automation capabilities and use cases can elevate your security organization-wide, and “AI-driven ransomware protection at machine speed: Defender for Endpoint” (BRK325), which will dive into the key secret to the success of Defender for Endpoint customers in reducing the risk of ransomware attacks as well maximizing the value of the product’s new features and user interfaces.

Explore cybersecurity tools with product showcases and hands-on training

Learning about Microsoft security capabilities is useful, but there’s nothing like trying out the solutions for yourself. Our in-depth showcases and hands-on trainings give you the chance to explore these capabilities for yourself. Bring a notepad and your laptop and let’s put these tools to work.

  • “Secure access at the speed of AI with Copilot in Microsoft Entra” (THR556): Learn how AI with Security Copilot and Microsoft Entra can help you accelerate tasks like troubleshooting, automate cybersecurity insights, and strengthen Zero Trust.  
  • “Mastering custom plugins in Microsoft Security Copliot” (THR653): Gain practical knowledge of using Security Copilot’s capabilities during a hands-on session aimed at security and IT professionals ready for advanced customization and integration with existing security tools. 
  • “Getting started with Microsoft Sentinel” (LAB452): Get hands-on experience on building detections and queries, configuring your Microsoft Sentinel environment, and performing investigations. 
  • “Secure Azure services and workloads with Microsoft Defender for Cloud” (LAB457): Explore how to mitigate security risks with endpoint security, network security, data protection, and posture and vulnerability management. 
  • “Evolving from DLP to data security with Microsoft Preview” (THR658): See for yourself how Microsoft Purview Data Loss Prevention (DLP) integrates with insider risk management and information protection to optimize your end-to-end DLP program. 

Network with Microsoft and other industry professionals

While you’ll gain a wealth of insights and learn about our latest product innovations in sessions, our ancillary events offer opportunities to connect and socialize with Microsoft and other security professionals as committed to you to strengthening the industry’s defenses against cyberthreats. That’s worth celebrating!

  • Pre-day Forum: All Chicago Microsoft Ignite attendees are welcome to add on to the event with our pre-day sessions on November 18, 2024, from 1 PM CT to 5 PM CT. Topics covered will include threat intelligence, Microsoft’s Secure Future Initiative, AI innovation, and AI security research, and the event will feature a fireside chat with Microsoft partners and customers. The pre-day event is designed for decision-makers from businesses of all sizes to advance your security strategy. If you’re already attending in person, log in to your Microsoft Ignite registration and add on the Microsoft Security Ignite Forum.
  • Security Leaders Dinner: We’re hosting an exclusive dinner with leaders of security teams, where you can engage with your peers and provide insights on your greatest challenges and successes. This intimate gathering is designed specifically for CISOs and other senior security leaders to network, share learnings, and discuss what’s happening in cybersecurity.   
  • Secure the Night Party: All security professionals are encouraged to celebrate the cybersecurity community with Microsoft from 6 PM CT to 10 PM CT on Wednesday, November 20, 2024. Don’t miss this opportunity to connect with Microsoft Security subject matter experts and peers at our “Secure the Night” party during Microsoft Ignite in Chicago. Enjoy an engaging evening of conversations and experiences while sipping tasty drinks and noshing on heavy appetizers provided by Microsoft. We look forward to welcoming you. Reserve your spot today

Something that excites us the most about Microsoft Ignite is the opportunity to meet with cybersecurity professionals dedicated to modern defense. Stop by the Microsoft Security Expert Meetup space to say hello, learn more about capabilities you’ve been curious about, or ask questions about Microsoft’s cybersecurity efforts. 

Hear from our Microsoft Intelligent Security Association partners at Microsoft Ignite

The Microsoft Intelligent Security Association (MISA), comprised of independent software vendors (ISV) and managed security service providers (MSSPs) that have integrated their solutions with Microsoft’s security technology, will be back at Microsoft Ignite 2024.

We kick things off by celebrating our Security Partner of the Year award winners BlueVoyant (Security), Cyclotron (Compliance), and Inspark (Identity) who will join Vasu Jakkal for a fireside chat on “How security strategy is adapting for AI,” during the Microsoft Ignite Security Pre-day Forum. This panel discussion includes insights into trends partners are seeing with customers relating to AI, a view on practical challenges, and scenarios that companies encounter when deploying AI, as well as the expert guidance and best practices that security partners can offer to ensure successful AI integration in security strategies.

MISA is thrilled to welcome small and medium business (SMB) verified solution status to its portfolio. This solution verification highlights technology solutions that are purpose built to meet the needs of small and medium businesses, and the MSSPs who often manage IT and security on behalf of SMBs. MISA members who meet the qualifying criteria and have gone through engineering review, will receive a specialized MISA member badge showcasing the verification and will be featured in the MISA partner catalog. We are excited to launch this status with Blackpoint Cyber and Huntress.

Join MISA members including Blackpoint Cyber and Huntress at the Microsoft Expert Meetup Security area where 14 members will showcase their solutions and Microsoft Security Technology. Review the full schedule below.

Graphic showing the MISA partner schedule at Microsoft Ignite 2024.

We are looking forward to connecting with our customers and partners at the Microsoft Secure the Night Party on Wednesday, November 20, from 6 to 10 PM CT.  This evening event offers a chance to connect with Microsoft Security subject matter experts and MISA partners while enjoying cocktails, great food, and entertainment. A special thank you to our MISA sponsors: Armor, Cayosoft, ContraForce, HID, Lighthouse, Ontinue, and Quorum Cyber.

Register today to attend Microsoft Ignite online

There’s still time to register to participate in Microsoft Ignite online from November 19 to 22, 2024, to catch security-focused breakout sessions, product demos, and participate in interactive Q&A sessions with our experts. No matter how you participate in Microsoft Ignite, you’ll gain insights on how to secure your future with an AI-first, end-to-end cybersecurity approach to keep your organizations safer.

Plus, you can take your security knowledge further at Tech Community Live: Microsoft Security edition on December 3, 2024, to ask all your follow-up questions from Microsoft Ignite. Microsoft Experts will be hosting live Ask Microsoft Anything sessions on topics from Security for AI to Copilot for Security.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us at @MSFTSecurity for the latest news and updates on cybersecurity.

The post Microsoft Ignite: Sessions and demos to improve your security strategy appeared first on Microsoft Security Blog.

]]>
Connect with Microsoft Security at Black Hat USA 2024​​ http://approjects.co.za/?big=en-us/security/blog/2024/07/17/connect-with-microsoft-security-at-black-hat-usa-2024/ Wed, 17 Jul 2024 16:00:00 +0000 Join Microsoft Security leaders and other security professionals from around the world at Black Hat USA 2024 to learn the latest information on security in the age of AI, cybersecurity protection, threat intelligence insights, and more.​

The post Connect with Microsoft Security at Black Hat USA 2024​​ appeared first on Microsoft Security Blog.

]]>
Black Hat USA 2024 is packed with timely, relevant information for today’s security professionals. During the conference this August, we’ll share our deep expertise in AI-first end-to-end security and extensive threat intelligence research. Join us as we present our main stage speaker Ann Johnson, Corporate Vice President and Deputy Chief Information Security Officer (CISO) of Microsoft Security, as she shares threat intelligence insights and best practices from the Office of the CISO in her conversation with Sherrod DeGrippo, Director of Threat Intelligence Strategy at Microsoft Threat Intelligence Center (MSTIC).  

Also at Black Hat, our Microsoft AI Red Team will be onsite holding training sessions, briefings, and panel discussions. And today, we’re releasing a white paper to demonstrate the impact of red teaming in practice when incorporated in the AI development life cycle. The paper details our innovative “Break-Fix” approach to red teaming AI systems and our close collaboration with Microsoft’s Phi-3 team, which allowed us to reduce the harms by 75% in Microsoft’s state-of-the-art small language models.1   

As a proud sponsor of the inaugural AI Summit at Black Hat, we’re further investing in the community by sharing our learnings in both AI for Security and Securing AI. We’ll be participating in a panel discussion titled “Balancing Security and Innovation—Risks and Rewards in AI-Driven Cybersecurity,” where we’ll debate the trade-offs between innovation in AI and security risks and share strategies to foster innovation while maintaining robust security postures.  

There’s also a sponsored session titled “Moonstone Sleet: A Deep Dive into their TTPs,” presented by Greg Schloemer, Threat Intelligence Analyst at Microsoft, that takes a deep dive into cyber threat actors associated with the Democratic People’s Republic of Korea (DPRK), as well as educational and engaging theater sessions in our Microsoft booth #1240. With a ton of critical security content to catch—all detailed below—we hope you’ll make time to connect with us at Black Hat 2024. 

Plan your schedule with our standout sessions  

Join us for core Black Hat sessions, submitted for consideration by Microsoft subject matter experts and selected by the Black Hat content committee to be included in its main agenda.  

DATE & TIME SESSION TITLE  INFORMATION SPEAKER(S) 
Saturday, August 3, to Tuesday, August 6, 2024  AI Red Teaming in Practice Hands-on training on how to red team AI systems and strategies to find and fix failures in state-of-the-art AI systems. Dr. Amanda Minnich, Senior Researcher, Microsoft;  
Gary Lopez, Researcher, Microsoft; 
Martin Pouliot, Researcher, Microsoft  
Wednesday, August 7, 2024, 10:20 AM PT-11:00 AM PT Breaching AWS Accounts Through Shared Resources   Presenting six critical vulnerabilities that we found in AWS, along with the stories and methodologies behind them. Yakir Kadkoda, Lead Security Researcher, Aqua Security; 
Michael Katchinskiy, Security Researcher, Microsoft; 
Ofek Itach, Senior Security Researcher, Aqua Security 
Wednesday, August 7, 2024, 12:40 PM PT-1:50 PM PTHacking generative AI with PyRIT Understand the presence of security and safety risks within generative AI systems with PyRIT. Raja Sekhar Rao Dheekonda, Senior Software Engineer, Microsoft 
Wednesday, August 7, 2024, 3:20 PM PT AI Safety and You: Perspectives on Evolving Risks and Impacts Panel on the nuts and bolts of AI Safety and operationalizing it in practice. Dr. Amanda Minnich, Senior Researcher, Microsoft;  
Nathan Hamiel, Senior Director of Research, Kudelski Security;  
Rumman Chowdhury; 
Mikel Rodriguez, Research Scientist, Google Deepmind 
Wednesday, August 7, 2024, 1:30 PM PT-2:10 PM PT Predict, Prioritize, Patch: How Microsoft Harnesses LLMs for Security Response  A crash course into leveraging Large Language Models (LLMs) to reduce the impact of tedious security response workflows. Bill Demirkapi, Security Engineer, Microsoft Security Response Center 
Wednesday, August 7, 2024, 3:20 PM PT-4:00 PM PTCompromising Confidential Compute, One Bug at a Time Review of methodology and the emulation tooling developed for security testing purposes, and how it influenced our understanding and review strategy. Ben Hania, Senior Security Researcher, Microsoft; Maxime Villard, Security Researcher, Microsoft; Yair Netzer, Principal Security Researcher, Microsoft 
Thursday, August 8, 2024, 10:20 AM PT-11:00 AM PTOVPNX: 4 Zero-Days Leading to RCE, LPE and KCE (via BYOVD) Affecting Millions of OpenVPN Endpoints Across the Globe Microsoft identified vulnerabilities in OpenVPN that attackers could chain and remotely exploit to gain control over endpoints. Vladimir Tokarev, Senior Security Researcher, Microsoft 
Thursday, August 8, 2024, 1:30 PM PT-2:10 PM PT  Locked Down but Not Out: Fighting the Hidden War in Your BootloaderA deep dive into the systemic weaknesses which undermine the security of your boot environment. Bill Demirkapi, Security Engineer, Microsoft Security Response Center 

Stop by our booth (1240) to connect with Microsoft security experts  

At Black Hat 2024, Microsoft Security is here with security leaders and resources that include:   

  • Threat researchers and security experts from Microsoft Security, here to connect with the community and share insights.  
  • Live demos of Microsoft Copilot for Security, informed by the 78 trillion signals Microsoft processes daily, to help security pros be up to 22% faster. 2
  • Theater presentations of Microsoft’s unified security operations experience, which brings together extended detection and response (XDR) and security information and event management (SIEM), so you get full visibility into cyberthreats across your multicloud, multiplatform environment.  
  • Hands-on experience with Microsoft Security solutions to help you adopt AI safely.  

Connect with Microsoft leaders and representatives to learn about our AI-first end-to-end security for all. Additionally, you’ll be able to view multiple demonstrations on a wide range of topics including threat protection, securing AI, multicloud security, Copilot for Security, data security, and advanced identity. You’ll also be able to connect with our Microsoft Intelligent Security Association (MISA) partners during your visit—the top experts from across the cybersecurity industry with the shared goal of improving customer security worldwide. And if you have specific questions to ask, sign up for a one-on-one chat with Microsoft Security leaders. 

Partner presence at the Microsoft booth

At the Theater in the Microsoft booth, watch our series of presentations and panels featuring Microsoft Threat Intelligence Center (MSTIC) experts and Microsoft Researchers. Half of the sessions will be presented by the MSTIC Team. The Microsoft booth will also feature sessions from select partners from the Microsoft Intelligent Security Association (MISA). MISA is an ecosystem of leading Security companies that have integrated their solutions with Microsoft Security technology with a goal of protecting our mutual customers from cybersecurity threats. Seven partners will showcase their solutions at our MISA demo station and five partners will be presenting their solutions in our mini-theater. We would love to see you there. Click here to view our full theater session schedule. 

Decorative graphic listing the partners that will be featured at the MISA theater sessions at Black Hat USA 2024.
Decorative graphic listing the MISA demo sessions at the Microsoft Booth at Black Hat USA 2024.

Reserve your spot at the Microsoft Security VIP Mixer  

The event will be co-hosted by Ann Johnson, Corporate Vice President and Deputy CISO of Microsoft Security, and Aarti Borkar, Vice President of Microsoft Security, Customer Success and Microsoft Incident Response, and, we are thrilled to have five MISA partners—Avertium, BlueVoyant, NCC Group, Trustwave, and Quorum Cyber—sponsoring our Microsoft Security VIP Mixer. The mixer is a great time to connect and network with fellow industry experts, and grab a copy of Security Mixology, a threat intelligence-themed cocktail and appetizer cookbook—you’ll be able to meet some of the contributors! Drinks and appetizers will be provided. Reserve your spot to join us at this exclusive event.

Flyer advertising the Microsoft Security VIP Mixer at Black Hat USA 2024.

Don’t miss the AI Summit at Black Hat  

On Tuesday, August 6, 2024, from 11:10 AM PT to 11:50 AM PT, we’ll be part of a panel discussion titled “Balancing Security and Innovation—Risks and Rewards in AI-Driven Cybersecurity.” Microsoft is honored to be a VisionAIre sponsor for this event. Brandon Dixon, Partner Product Manager, Security AI Strategy will debate the trade-offs between innovation in AI and security risks, share strategies to foster innovation while maintaining robust security, and more. Note: The AI Summit is a separate, one-day event featuring technical experts, industry leaders, and security tsars, designed to give attendees a comprehensive understanding of the potential risks, challenges, and opportunities associated with AI and cybersecurity.  

Microsoft’s Most Valuable Researchers 

Security researchers are a critical part of the defender community, on the front lines of security response evolution, working to protect customers and the broader ecosystem. On Thursday, August 8, 2024, we’ll host our invite-only Microsoft Researcher Celebration. And on August 6, 2024, Microsoft Security Response Center (MSRC) will announce the annual top 100 Most Valuable Researchers (MVRs) who help protect our customers through surfacing and reporting security vulnerabilities under Coordinated Vulnerability Disclosure (CVD). Follow @msftsecresponse on X and Microsoft Security Response Center on LinkedIn for the MVR reveal. 

Secure your future with Microsoft global-scale threat intelligence  

In the hands of security professionals and teams, AI can deliver the greatest advantage to organizations of every size, across every industry, tipping the scales in favor of defenders. Microsoft is bringing together every part of the company in a collective mission to advance cybersecurity protection to help our customers and the security community. We offer four powerful advantages to drive security innovation: large-scale data and threat intelligence; the most complete end-to-end protection; industry leading, responsible AI; and the best tools to secure and govern the use of AI. Together we can propel innovation and create a safer world. We’re excited to share the latest product news and Microsoft Security innovations during Black Hat 2024 and we hope to see you there.  

Join us at the Microsoft Security VIP Mixer

Don’t miss this opportunity to connect with Microsoft Security experts and fellow industry leaders—and pick up your copy of Security Mixology!

For more threat intelligence guidance and insights from Microsoft security experts, visit Security Insider

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity. 


Sources:

1Phi-3 Technical Report: A Highly Capable Language Model Locally on Your Phone, Microsoft. April 2024.

2Microsoft Copilot for Security is generally available on April 1, 2024, with new capabilities, Vasu Jakkal. March 13, 2024.

The post Connect with Microsoft Security at Black Hat USA 2024​​ appeared first on Microsoft Security Blog.

]]>
Explore Microsoft’s AI innovations at RSA Conference 2024 http://approjects.co.za/?big=en-us/security/blog/2024/04/04/explore-microsofts-ai-innovations-at-rsa-conference-2024/ Thu, 04 Apr 2024 16:00:00 +0000 Will you be at the RSA Conference? Join us for Microsoft Pre-Day, sessions, and other events for insights on leading in AI. Keep reading for what to expect at the event.

The post Explore Microsoft’s AI innovations at RSA Conference 2024 appeared first on Microsoft Security Blog.

]]>
The security of your organization directly correlates with your ability to transform and achieve your business objectives. Microsoft can help you make that happen, with our powerful combination of large-scale data and threat intelligence, end-to-end protection, and responsible AI. ​

Recently at Microsoft Secure, we shared our latest innovations for securing and governing AI and announced the generative AI solution for cyberdefenders: Microsoft Copilot for Security. We’re excited to talk with you about how to bring these innovations to life in your organization at the RSA Conference (RSAC), May 6 to 9, 2024, in San Francisco.

At the conference, we’ll demonstrate how to secure and govern AI and benefit from end-to-end protection with solutions across the Microsoft Security portfolio, including Microsoft Copilot for Security. We’ll show you how we help security teams build their skills faster to protect their organizations.

Join us a day early, on Sunday, May 5, 2024, at Microsoft Pre-Day to kick-off RSA Conference 2024, and hear directly from our Microsoft Security Business leaders, including Vasu Jakkal, Corporate Vice President, Microsoft Security Business, and Charlie Bell, Executive Vice President, Microsoft Security. Plus, view live demos at a variety of Microsoft sessions happening throughout the conference in breakout rooms and at our booth #6044N.

Microsoft Pre-Day: Hear from Microsoft Security product leaders

Start the conference on a high note by joining us for the Microsoft Pre-Day at the Microsoft Security Hub beginning at 4:00 PM PT on Sunday, May 5, 2024. For chief information security officers (CISOs) and cybersecurity professionals, we invite you to dive deeper into the latest AI announcements, learn about new product capabilities, and gain peace of mind of how to secure AI as you introduce the technology into your organization.

Vasu Jakkal and other Microsoft leaders will share our perspectives on topics like AI-powered security, innovations in end-to-end protection, and solutions to secure AI. We’ll also be joined by Microsoft customers who will share how they have been successful in their security evolution.

Pre-Day will continue with a Q&A session with Vasu Jakkal, Charlie Bell, and other leaders. They’ll reflect on the latest developments in cybersecurity, AI, and how the global community of cyber professionals can work together for a more secure future.

a group of people sitting in chairs

The conclusion of Pre-Day will be an evening reception at 6:00 PM PT, where you will have an opportunity to network with other professionals over drinks and appetizers.

Microsoft keynote and sessions: Get valuable insights and inspiration

Once the RSA Conference begins, you’ll have several opportunities to attend demos and connect one-on-one with Microsoft product experts. Mark your calendar on Tuesday, May 7, 2024, to visit our keynote in the official conference line up from 3:40 PM PT to 4:00 PM PT at Moscone West. Vasu Jakkal will share insights on how AI is evolving, its impact on the threat landscape, and what every organization should do to keep it safe.

While there is a lot of hype around AI, most security professionals are taking a risk-averse approach. This means that employees will find workarounds to use generative AI. Join Brian Fielder, Vice President of Security Engineering at Microsoft, who will talk about Microsoft’s approach to securing and governing AI.  You will walk away with practical guidance on governing AI, how to ensure data privacy, and compliance.

Check out one or all of our Microsoft Security sessions included in the RSA Conference agenda. Here are just a few you won’t want to miss:

  • “Hiding in Plain Sight: Hunting Volt Typhoon Cyber Actors.” Monday, May 6, 2024, 2:20 PM PT to 3:10 PM PT. Explore how the private sector and United States government work together to identify activity of the Volt Typhoon cyberthreat. Get lessons learned from Volt Typhoon’s tactics, techniques, and procedures, and how network defenders can best defend themselves. Kelly Bissell, Deputy CISO and CVP, Security Services, Microsoft; Cynthia Kaiser, Deputy Assistant Director, FBI; Morgan Adamski, Chief NSA Cybersecurity Collaboration Center, DOD; and Andrew Scott, Associate Director for China Operations, CISA; will share insights.
  • “AI Safety: Where’s the Puck Headed?” Wednesday, May 8, 2024, 9:40 AM PT to 10:30 AM PT. Hear from a panel of experts—Ram Shankar Siva Kumar Data Cowboy, Microsoft; Vijay Bolina, CISO, Head of Cybersecurity Research, Google DeepMind; Rumman Chowdhury, Responsible AI Fellow, Berkman Klein Center, Harvard University; Dan Hendrycks, Founder, Center for AI Safety; and Daniel Rohrer, Vice President of Software Product Security—Architecture and Research, NVIDIA—on what AI safety means, why it rose to prominence, and what this means for the future of AI and cybersecurity.
  • “From Attribution to Accountability: Upholding International Rules Online.” Wednesday, May 8, 2024, 1:15 PM PT to 2:05 PM PT. Get insights from a panel of litigation experts on how governments and the private sector can improve their public attribution efforts and ensure they are working cooperatively to advance respect for international rules online. The panel will include Amy Hogan-Burney, Associate Counsel and General Manager, Cybersecurity Policy and Protection, Microsoft; Megan Stifel, Chief Strategy Officer, Institute for Security and Technology; Liesyl Franz, Deputy Assistant Secretary for International Cyberspace Security, United States Department of State; Jonathan Horowitz, Legal Advisor, International Committee of the Red Cross; and William Middleton of the Foreign, Cyber Director, Foreign, Commonwealth and Development Office.

You can also stop by our Security Hub, located at The Palace Hotel, at any time to view an additional lineup of sessions well worth exploring, highlighting a few:

  • “A Year of Microsoft Copilot for Security.” Monday, May 6, 2024,10:30 AM PT to 11:30 AM PT. Join us as we reflect on 12 months of learning from early customers, listen to their real-world experiences, dive into research on how Copilot for Security can elevate productivity with optimized security and catch a sneak peek into the future of generative AI in security. 
  • “Threat intelligence trends and insights breakfast panel.”: Tuesday, May 7, 2024, 8:00 AM PT to 9:00 AM PT. Attend an exclusive briefing featuring experts from the Microsoft Threat Intelligence team, who analyze 78 trillion signals daily to uncover emerging threats. They will share insights and guidance on nation-state actors, cybercrime takedowns, fraud and social engineering, and cyber influence operations. 
  • AI Safety lunch and fireside chat: Tuesday, May 7, 2024, 12:00 PM PT to 1:30 PM PT. Join Sarah Bird, Chief Product Officer of Responsible AI, and Bret Arsenault, Chief Cybersecurity Advisor, where we’ll address CISOs’ top AI concerns, the importance of responsible AI, and Microsoft’s commitment to AI safety. Walk away with practical guidance on implementing AI safely in your organization. 
  • “Zero Trust for AI Security Leaders session.” Tuesday, May 7, 2024, 2:30 PM PT to 3:15 PM PT. Gain a deeper understanding of the five top risks inherent to generative AI and how Zero Trust for AI can help your organization deploy and use AI securely. You will walk away from this session with a Zero Trust for AI framework and a copy of the book signed by the author and presenter Mark Simos.

Visit Microsoft Security Hub at The Palace Hotel  

Join us for these sessions and more at the Microsoft Security Hub. Don’t miss out on the opportunity to explore all our sessions and ancillary events, plus you can also engage in a gamified experience dedicated to AI for security and have the chance to win exciting prizes. Additionally, you can schedule meetings with Microsoft experts and delve into the Cyber Threat Intelligence Program’s (CTIP) interactive experience from the Microsoft Digital Crimes Unit (DCU), where you’ll be able to explore the world of the malware sinkhole. The CTIP collects actionable cyberthreat intelligence from its malware disruption operations and uses this data to inform Microsoft products and services. Leveraging unique insights from Microsoft Threat Intelligence, the DCU disrupts cybercriminals’ technical infrastructure through civil legal actions, technical measures, criminal referrals to law enforcement, and public and private partnerships.

Register now to attend a variety of sessions at the Microsoft Security Hub, hosted at the historical Palace Hotel.

Stop by Microsoft Security booth at Moscone North  

The Microsoft booth will be located this year in Moscone North, close to the entrance, and will feature demos of Microsoft Security portfolio, theater presentations, gamified experience focused on Security for AI, and interactive DCU experience. Have some refreshments amidst your busy conference day and get your copy of the books about Zero Trust and Threat Intelligence signed by the authors.  

Drop by the theater at the the Microsoft booth to hear from our experts on the latest news and demos on AI, threat protection, secure access, data governance, cloud security, privacy, Zero Trust, and more. 

Participate in conversations on the future of cybersecurity

While at RSAC, consider participating in other events that will connect you with cybersecurity professionals and spark interesting conversation about the future of cybersecurity and AI.

  • CSA AI Summit​: Monday, May 6, 2024, 12:10 PM PT to 12:30 PM PT. Get a front-row seat to Microsoft Security for AI innovations as part of the summit. Led by Microsoft Senior Product Marketing Manager Tina Ying, our session will focus on Security for AI. The CSA AI Summit, from 8:00 AM to 3:00 PM PT on Level 3 of Moscone Center South, will explore the intersection of AI and cloud and offer best practices on how to make the most of the AI revolution. More than 1,100 cybersecurity leaders and professionals are expected to attend the summit.
  • Women in Cybersecurity (WiCyS) Meetup: ​Tuesday, May 7, 2024, 6:30 PM PT to 7:30 PM PT. Learn how WiCyS is introducing more women to cybersecurity—and how you can support these endeavors. The meetup will spotlight the achievements of WiCyS, established in 2012 to increase the number of women in cybersecurity roles by giving them mentorships, networking opportunities, and access to training and resources.
a group of people looking at a cell phone

Microsoft Partners: Networking opportunity and Security Excellence Awards celebration

The Microsoft Intelligent Security Association (MISA), comprised of independent software vendors (ISV) and managed security service providers (MSSPs) that have integrated their solutions with Microsoft’s security products, will be back at RSAC 2024. MISA will again have a demo station at Microsoft Booth #6044N in Moscone North Expo among other events, including the fifth annual Microsoft Security Excellence Awards (presented by MISA).

MISA’s RSAC 2024 presence will include:

  • MISA Demo Station: Stop by Microsoft Booth #6044N Monday, May 6, 2024, to Thursday, May 9, 2024, for demonstrations of Microsoft products.
  • Theater sessions: Join one or more of our five theater sessions for valuable insights focused on how MISA members work together with Microsoft to protect customers from cyberthreats. Led by MISA members, these sessions will focus on strategies to protect customers from cyber threats. The sessions will feature expertise from partners Bulletproof, ContraForce, Darktrace, Avanade, Kovrr, and glueckkanja AG.
  • Hub sessions: Join MISA members for a one-hour session on top-of-mind security topics in the Microsoft Security Hub.
  • Partner awards: MISA members are invited to attend the Microsoft Security Excellence Awards on Monday, May 6, 2024, where winners will be announced in nine security award categories.

Congratulations to the finalists of the 2024 Excellence Awards!

Connect with Microsoft at RSAC

Register today for the Microsoft Security RSAC Pre-Day on May 5, 2024 from 4:00 PM PT to 6:00 PM PT. Explore our sessions, receptions, and other events. Leverage this opportunity to learn and connect. Stop by our booth #6044N to ask questions. Enjoy conversation or simply say hello. Looking forward to seeing you at RSAC!

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post Explore Microsoft’s AI innovations at RSA Conference 2024 appeared first on Microsoft Security Blog.

]]>
How to connect with Microsoft Security at Black Hat USA 2023 http://approjects.co.za/?big=en-us/security/blog/2023/07/27/how-to-connect-with-microsoft-security-at-black-hat-usa-2023/ Thu, 27 Jul 2023 16:00:00 +0000 Learn more about the sessions, product demos, and special events presented by Microsoft at Black Hat 2023.

The post How to connect with Microsoft Security at Black Hat USA 2023 appeared first on Microsoft Security Blog.

]]>
Now in its twenty-sixth year, Black Hat USA takes place August 5 to 10, 2023, at Mandalay Bay in Las Vegas, Nevada, bringing together security professionals for the latest in information security research, development, and trends. Microsoft Security is pleased to have a presence at Black Hat, with exciting sessions, product demos and meetings at our booth, and a customer happy hour—all designed to inform and engage attendees with the latest thought leadership, trends, and news related to threat protection. We hope you’ll join us, and read on to learn more about what we’re bringing to Black Hat.

Connect with Microsoft security experts at Black Hat

Be sure to stop by the Microsoft Security booth number 1740 to view our Microsoft Threat Intelligence Interactive Experience, view product demonstrations in our mini-theater, and chat with Microsoft representatives about your company’s priorities and how Microsoft Security can help you defend against threats across all endpoints and clouds. Product demonstrations will cover cloud security, threat protection products including Microsoft Security Copilot, Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, Microsoft Defender for IoT, Azure Network Security (Microsoft Azure DDoS Protection, Web Application Firewall, Microsoft Azure Firewall), threat intelligence including Microsoft Defender Threat Intelligence, and Microsoft Entra. You’ll also be able to connect with our Microsoft Intelligent Security Association (MISA) partners during your visit. These are top experts from across the cybersecurity industry with the shared goal of improving customer security.

Two people having a conversation at the Microsoft Security Booth at Black Hat Conference 2022.

This year at Black Hat USA, we’re excited to have a mini-theater right in our booth to share the latest thought leadership, trends, and product innovations. These are a few highlighted sessions:

SESSION TITLESPEAKER
Automating Threat Hunting with MDTI—Revealing Threat Infrastructure at ScaleGeoff Roote, Senior Security Specialist, Microsoft
Microsoft Security CopilotRyan Munsch, Principal Solution Specialist, Microsoft
Simplify your defense against threats with Microsoft SentinelBenjamin Powell, Senior Product Marketing Manager, Microsoft
Introducing the Microsoft Incident Response RetainerHolly Burmaster, Associate Cybersecurity Consultant, Microsoft Incident Response
Unify cloud security protections with Microsoft Defender for Cloud, Microsoft’s comprehensive cloud-native application protection platformThomas Zou, Product Marketing Manager, Microsoft
Microsoft Bug Bounty ProgramMadeline Eckert, Senior Program Manager, Microsoft

See the full schedule of sessions presented in our mini-theater.

Our mini-theater will also feature sessions by members of MISA including Red Canary, Quorum Cyber, Ontinue, PwC, Synack, and Vectra AI. See the full MISA schedule.

On Wednesday, August 9, 2023, from 6 PM PT to 8 PM PT at Lupo by Wolfgang Puck, we’ll be connecting and networking with fellow industry experts at our exclusive customer happy hour; drinks and appetizers will be provided. The event will be co-hosted by Kelly Bissell, Corporate Vice President, Microsoft Security, and Aanchal Gupta, Corporate Vice President and Deputy Chief Information Security Officer (CISO), Microsoft Security. This customer happy hour is made possible by event sponsors Red Canary, Quorum Cyber, Ontinue, PwC, and Synack.

Microsoft Security sessions on AI, threat protection, and more

Microsoft Security delivers one of the most comprehensive solutions to help you defend against threats across all endpoints and clouds. To that end, at this year’s Black Hat, we’re presenting unique AI and threat protection sessions.

  • AI: Defending at machine speed with Microsoft Security—Scott Woodgate, Senior Director of Security Marketing, will discuss how Microsoft is applying AI and machine learning to disrupt attackers’ traditional advantages, adapt to their new techniques, and combat the growing scale of the industrialization of cybercrime. See how Microsoft extended detection and response (XDR) can automatically disrupt in-progress attacks, how Security Copilot will help simplify security operations center (SOC) investigations, and more. Wednesday, August 9, 2023, from 11:30 AM PT to 11:50 AM PT.
  • Risks of AI Risk Policy: Five Lessons—Ram Shankar Siva Kumar, Data Cowboy, Microsoft, and Jonathan Penney, Associate Professor, Osgoode Hall Law School, will talk about the rapid proliferation of AI Risk Management standards and frameworks (21 and growing). We’ll show how two popular AI Risk Management frameworks lack actionable security guidance, are too vague, and fail to account for civil liberties implications. Learn how to create standards that work and unblock machine learning engineers and security professionals deploying AI. , August 9, 2023, from 11:20 AM PT to 11:40 AM PT.
  • ICS Forensics Tools—Ori Perez and Maayan Shaul, Senior Security Researcher, Microsoft, will announce two new tools in the ICS Forensics Tools arsenal, the open-source forensic toolkit for analyzing industrial programmable logic controller (PLC) metadata and project files. Tools will be available for immediate use right before the session begins. Thursday, August 10, 2023, from 1:00 PM PT to 2:30 PM PT.
  • A SSLippery Slope: Unraveling the Hidden Dangers of Certificate Misuse—Bill Demirkapi, Security Engineer, Microsoft Security Response Center, discusses systemic vulnerability uncovered in numerous signature validation implementations which allows attackers to exploit valid certificates in an unintended manner. Wednesday, August 9, 2023, from 3:20 PM PT to 4:00 PM PT.
  • CoDe16; 16 Zero-Day Vulnerabilities Affecting CODESYS Framework Leading to Remote Code Execution on Millions of Industrial Devices Across Industries​—Vladimir Eliezer Tokarev, Security Researcher, Microsoft, presents 16 zero-day vulnerabilities found in CODESYS—a platform-independent software framework used for programming PLCs. Thursday, August 10, 2023, from 4:20 PM PT to 5:00 PM PT.
  • Second Breakfast: Implicit and Mutation-Based Serialization Vulnerabilities in .NET—Jonathan Birch, Principal Software Security Engineer, Microsoft, discusses novel attacks against .NET serialization that bypass current state-of-the-art mitigations and violate typical assumptions regarding serializer security. Wednesday, August 9, 2023, from 2:30 PM PT to 3:00 PM PT.
  • Blue Teaming For Your Mental Health—There’s no question that any role within the cyber security industry is mentally taxing. Sarah Young, Senior Cloud Security Advocate, Microsoft, will share how she learned to manage her mental health whilst coping with exacerbating factors from one of her previous cyber security jobs. Thursday, August 10, 2023, from 2:00 PM PT to 2:40 PM PT.

Celebrating the security community together

On Thursday, August 10, 2023, we will host our researcher community for an invite-only Microsoft Researcher Celebration. Our security team is looking forward to meeting and talking with our peers from across the industry as we celebrate our close partnerships to keep the world safe. As always, we celebrate the diverse community of security researchers who work with our team every day.

Attendees at a Microsoft networking event.

At Microsoft, we believe in the transformative power of engaging many different perspectives. Different perspectives help us all to achieve more, and we’re committed to leveraging our global influence to drive positive change. This year, we’re excited to be a Signature sponsor of the Cybersecurity Woman of the Year Awards Gala in Las Vegas, on August 8, 2023, at the Luxor hotel.

If you can, stick around after Black Hat for SquadCon. Happening nearby and taking place right after Black Hat, our Microsoft Security Response Center is excited to sponsor SquadCon, the reimagined cybersecurity conference where inclusivity is a core concept. Brought to you by BlackGirlsHack and powered by Girls Hack Village, SquadCon takes place August 10 to 12, 2023, at the Industrial event space in Las Vegas. View the event page to learn more and get your tickets.

Lastly, we’re excited to share the latest product news and Microsoft Security innovations during Black Hat. Stay tuned for more information. We hope to see you at the conference. Have questions? Visit us at exhibition booth number 1740 and sign up for a time to chat.

In the meantime, explore resources to continue your learning on defending against threats with Microsoft Security.

Learn more

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and Twitter (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post How to connect with Microsoft Security at Black Hat USA 2023 appeared first on Microsoft Security Blog.

]]>
Discover a new era of security with Microsoft at RSAC 2023 http://approjects.co.za/?big=en-us/security/blog/2023/04/04/discover-a-new-era-of-security-with-microsoft-at-rsac-2023/ Tue, 04 Apr 2023 16:00:00 +0000 Microsoft Security will be at the 2023 RSA Conference and we’d love to connect with you there. In this blog post, we share all the ways you can—plus, attend the Pre-Day with Microsoft and watch the Microsoft Security Copilot demo.

The post Discover a new era of security with Microsoft at RSAC 2023 appeared first on Microsoft Security Blog.

]]>
We’re thrilled to participate and connect with you at RSA Conference 2023 (RSAC) from April 23 to 27, 2023, in San Francisco. Join your security peers as we welcome you to the new era of security—shaped by the power of OpenAI’s GPT-4 generative AI—and introduce to you the recently announced Microsoft Security Copilot.

Introducing Microsoft Security Copilot: Empowering defenders at the speed of AI

Microsoft Security Copilot is the first security product to enable defenders to move at the speed and scale of AI. Security Copilot combines this advanced large language model with a security-specific model from Microsoft. This security-specific model in turn incorporates a growing set of security-specific skills and is informed by Microsoft’s unique global threat intelligence and more than 65 trillion daily signals. Security Copilot also delivers an enterprise-grade security and privacy-compliant experience as it runs on Microsoft Azure’s hyperscale infrastructure.

Be sure to explore all Microsoft sessions happening at RSAC and mark your calendar for our keynote session featuring Vasu Jakkal, Corporate Vice President (CVP), Microsoft Security, Compliance, and Identity.

Defending at Machine Speed: Technology’s New Frontier
Tuesday, April 25, 2023
3:40 PM PT to 4:00 PM PT

Join your peers at Pre-Day with Microsoft

Jumpstart your week at Pre-Day with Microsoft on Sunday, April 23, 2023, starting at 4:00 PM PT—and gain a deeper understanding of what an AI-powered future means for cybersecurity, learn new comprehensive strategies to help you protect everything, network with your peers, hear the latest announcements, and meet Microsoft Security business and engineering leaders. In addition, we’ll host interactive panels, a keynote from Microsoft leadership, and an evening reception. Register for Pre-Day now.

4:00 PM PT to 4:05 PM PTWelcomeKelly Bissell, CVP, Microsoft Security
4:05 PM PT to 4:25 PM PTKeynote: Innovate with comprehensive securityVasu Jakkal
4:25 PM PT to 5:00 PM PTFireside Chat: How security strategy is adapting with new innovationCharlie Bell, Executive Vice President, Microsoft Security
Vasu Jakkal
Bret Arsenault, CVP, Microsoft Security and Chief Information Security Officer
Andy Elder, CVP, Microsoft Security Solution Area
5:00 PM PT to 5:40 PM PTInnovation deep dives: AI and Threat IntelligenceHolly Stewart, Principal Research Director, Microsoft Threat Intelligence
Jeremy Dallman, Principal Research Director, Microsoft Threat Intelligence
5:40 PM PT to 6:10 PM PTClosing remarks and Q&ACharlie Bell, Vasu Jakkal, Kelly Bissell, Bret Arsenault
6:10 PM PT to 8:30 PM PTEvening ReceptionNetwork with Microsoft leaders and peers

Join us at the Microsoft Booth for interactive demos and theater sessions

During the week, visit the Microsoft booth located at Moscone North Expo to interact with all the latest innovative technology demos (including Security Copilot), schedule a booth tour, discover the Threat Intelligence Interactive Experience, and participate in our more than 40 in-booth theater sessions. You’ll also be able to connect with our Microsoft Intelligent Security Association (MISA) partners during your visit. These are top experts from across the cybersecurity industry with the shared goal of improving customer security.

Visit the Microsoft Security Hub for networking events

The Microsoft Security Hub—at Ecosystem Coworking SF, 540 Howard Street, San Francisco—is another way to continue those security conversations outside the events happening at Moscone Center—and you can watch a demo of Security Copilot. The Microsoft Security Hub is the place to be for multiple learning opportunities and networking events throughout RSAC. Discover Microsoft’s unparalleled view of the threat landscape, explore threat actor profiles, and learn about the tactics, techniques, and procedures of cybercriminals at the Microsoft Threat Intelligence Interactive Experience (conference hours, Monday, April 24-Wednesday, April 26, 2023).

These include:

  • Data Security Executive Roundtable: Creating your data security strategy. Join Alym Rayani, General Manager, Microsoft Security, for a conversation with industry peers. Learn best practices for how security teams can efficiently prioritize their limited security resources on the highest risks and learn about Microsoft’s Adaptive Protection that helps organizations dynamically address their most critical data security risks. (Monday, April 24, 2023, 10:30 AM PT to 12:00 PM PT)
  • Diversity Executive Women’s Lunch: The power of diversity: Building a stronger cybersecurity workforce. Join us for this networking lunch, with a panel discussion moderated by Aarti Borkar, Vice President, Customer Success, Microsoft Security, and featuring Vasu Jakkal; Ann Johnson, CVP, Microsoft Security; Lynn Dohm, Executive Director, Women in Cybersecurity; and Tanya Janca, Founder and Chief Executive Officer, We Hack Purple. The discussion will focus on education and career pathways, allyship, and what we can do to influence and nurture more women in cybersecurity. (Monday, April 24, 2023, 12:30 PM PT 2:00 PM PT)
  • Secure and Connected Endpoints Breakfast: Join Jason Roszak, Chief Product Officer, Management, Microsoft Security, and Dilip Radhakrishnan, Partner Group Product Manager, Management, Microsoft Security, for breakfast and learn how a proactive approach to endpoint management will result in more secure and connected endpoints. New advanced Microsoft Intune Suite capabilities are unlocking cyber-hygiene for our customers. In this session, learn what’s available in the product today, the possibilities with expanded platforms, and how a proactive approach to endpoint management will help you keep cyberattacks away. (Tuesday, April 25, 2023, 7:00 AM PT to 8:30 AM PT)
  • Threat Intelligence Happy Hour hosted by Microsoft Security Experts. (Tuesday, April 25, 2023, 4:30 PM PT to 6:30 PM PT)
  • AI: Shaping Security Today and Into the Future: In a world of overwhelming security signals and limited trained defenders, AI empowers defenders to focus on what’s important and to respond faster than ever before.  Join Scott Woodgate, Senior Director, Microsoft Security, to learn how AI is an integral part of Microsoft’s security strategy, helping drive security operations center efficiency already with Microsoft Sentinel and Microsoft 365 Defender and now taking it to the next level with Microsoft Security Copilot, the first and only generative AI security product to help defend organizations at machine speed and scale. (Wednesday, April 26, 2023, 10:30 AM PT to 11:30 AM PT) 
  • Influencing the Future of Cyber Security Professionals: With new innovations like AI coming to the forefront, we can influence the culture in our organizations to be more cyber-aware and build a stronger cybersecurity workforce. Join our panel of experts to learn how fostering awareness, education, and diversity play an important role in developing a cybersecurity culture. The panel will also discuss how AI not only affects organizations’ cybersecurity culture but can enable the next generation of cybersecurity professionals. (Wednesday, April 26, 2023, 2:00 PM PT to 3:00 PM PT)

Sign up for key Microsoft Sessions

Vasu Jakkal speaking at the RSA Conference 2022.

Join Vasu Jakkal at the main Microsoft keynote, Defending at Machine Speed: Technology’s New Frontier, on Tuesday, April 25, 2023, from 3:40 PM PT to 4:00 PM PT at the Moscone Center. Vasu will examine key technologies that are reshaping the future of cybersecurity, augmenting human ingenuity, and how these breakthroughs in technology can help close the security gap.

Hear John Lambert, CVP, Microsoft Security Research, explore the topic of Intelligence and AI at the Convergence at Data and Threats—Wednesday, April 26, 2023, from 9:40 AM PT to 10:30 AM PT at the Moscone Center. In security, data at scale is transforming machine learning and threat intelligence, enabling security teams to be agile and adaptive against an ever-changing environment. The session will focus on how defenders are innovating threat prediction, prevention, and prioritization using threat intelligence and AI to reduce the impact of increasing threats.

Watch Ann Johnson present on Geopolitical Resilience: Why Operational Resilience Is No Longer Enough—Monday, April 24, 2023, from 2:20 PM PT to 3:10 PM PT. Hear global leaders discuss how emerging business, social, and political crises necessitate a new approach to resilience. More than operational recovery, organizations have new dimensions of risk to consider, including deglobalization, data sovereignty, sanctions, forced market exits, and more. Learn how to build resiliency in a fragmented world.

And explore the RSAC Agenda for sessions on responsible AI, growing cybersecurity talent, red teaming, Zero Trust for consumers, supply chain security, regulations, industry-specific threats, a United Nations cybercrime treaty, verifiable credentials, and Kubernetes.

Connect with MISA

Chart displaying the finalists for the Microsoft Security Excellence Awards 2023 from the Microsoft Intelligent Security Association.

Figure 2. Microsoft Intelligent Security Association finalists for the Microsoft Security Excellence Awards 2023. Finalists represent 11 award categories: Security Trailblazer, Compliance and Privacy Trailblazer, Identity Trailblazer, Zero Trust Champion, Security Software Innovator, Security Services Innovator, Security Customer Champion, Security Changemaker, Diversity in Security, Security Independent Software Vendor of the Year, and Security Managed Security Service Provider of the Year.

MISA—our ecosystem of independent software vendors (ISVs) and managed security service providers (MSSPs) with solutions integrated with Microsoft’s security technology—will have a demo station at Microsoft Booth 6044N in Moscone North Expo and host several events at RSAC, including the annual MISA and Microsoft Security Excellence Awards. MISA’s mission is to provide intelligent security solutions for our shared customers by extending across the security ecosystem to integrate signals, increase visibility, and protect our mutual customers against cyber threats.​ MISA’s RSAC presence will include:

  • Booth activities including MISA demos on Tuesday, April 25, 2023, Wednesday, April 26, 2023, and Thursday, April 27, 2023, and five theater sessions on Wednesday, April 26, 2023, during which MISA members will share how they work together with Microsoft to protect customers from cyberthreats.
  • Opportunity to schedule executive meetings with Maria Thomson (MISA lead) and Nomi Nazeer (MSSP Go-To Market Lead)
  • MISA members are invited to attend the Microsoft Security Excellence Awards on Monday, April 24, 2023, where winners will be announced in 11 security award categories.

The new era of security to help you protect everything

At Microsoft Security, we believe our most secure future requires an end-to-end approach with technology and people, empowered to defend with resilience from the start. A future where every defender is empowered with the technologies and expertise that enable them to reach their full potential. Technology will play an essential role in this journey, but successful security is, and will continue to be, a human endeavor. We’re excited to be on this journey with you and looking forward to hearing your insights and feedback at RSAC 2023. Remember to register for the Pre-Day with Microsoft event, which starts on Sunday, April 23, 2023, at 4:00 PM PT, and plan on stopping at the Microsoft booth in Moscone North Expo. We’ll see you there!

Learn more

Learn more about Microsoft Security Copilot.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and Twitter (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post Discover a new era of security with Microsoft at RSAC 2023 appeared first on Microsoft Security Blog.

]]>
Microsoft Security highlights from Black Hat USA 2022 http://approjects.co.za/?big=en-us/security/blog/2022/08/25/microsoft-security-highlights-from-black-hat-usa-2022/ Thu, 25 Aug 2022 16:00:00 +0000 Black Hat USA 2022 marked the twenty-fifth year that security researchers, security architects, and other security professionals have gathered to share the latest research, developments, and trends. Here are the highlights from the Microsoft Security booth.

The post Microsoft Security highlights from Black Hat USA 2022 appeared first on Microsoft Security Blog.

]]>
Black Hat USA 2022 marked the twenty-fifth year that security researchers, security architects, and other security professionals have gathered to share the latest research, developments, and trends. Microsoft was among the companies participating in the conference, which was from August 6 to 11, 2022, in Las Vegas, Nevada. This year’s event was hybrid, with some attendees attending in-person and others joining online.

We were excited to join members of the Black Hat security community representing 111 countries.1 Along with more than 17,000 in-person attendees—and more than 15,000 virtual attendees—we heard security insights and shared the latest in Microsoft Security solutions, including two new security solutions—Microsoft Defender Threat Intelligence to track threat actor activity and Microsoft Defender External Attack Surface Management to discover unknown and unmanaged resources that are visible and accessible from the internet.

Booth excitement

A picture of the Microsoft Security booth at the Black Hat USA 2022 Conference.

What energizes us the most about conferences like Black Hat is the opportunity to meet people. During the conference, we welcomed hundreds of security professionals to our booth. There, we talked about cybersecurity threats, shared our perspective on the need for comprehensive security, listened to their stories of cybersecurity challenges, and gave them demonstrations of the latest innovations from Microsoft Security in the threat intelligence and protection space, including Microsoft Defender Experts for Hunting.

We’re passionate about security and it’s always a thrill to be among others who feel the same way. Our team in the booth was kept happily busy. Some attendees chatted in groups of two or more while others crowded around four demo stations—Microsoft Security Experts, threat protection, threat intelligence, and identity and access management—to see how Microsoft product solutions can help catch what others miss.

During our Diversity and Inclusion Hour on Wednesday, Black Hat attendees gathered in the Microsoft booth to socialize and talk about diversity, equality, and inclusion in the workplace. As a bonus, Microsoft enlisted a professional photographer to take headshots for anyone who attended and wanted to update their LinkedIn profiles.

A group of people having a conversation in the circle.

Conference sessions

Microsoft Security team members stay up on the latest news, solutions, and strategies in the security world. We were thrilled when several of these security professionals received the opportunity to share their thought leadership insights with Black Hat attendees.

  • “Advancing Investigations with Threat Intelligence”: Microsoft Incident Response Consultant MacKenzie Brown shared how Microsoft’s Detection and Response Team (DART) harnesses the power of threat intelligence while in the trenches helping customers challenged by cyberattacks. MacKenzie also walked through how DART responded to recent threats from the North Korean nation-state actor believed to be behind HolyGh0st and Lapus$. 163 attendees viewed the session virtually, which you can watch here.
  • “AAD Joined Machines—The New Lateral Movement”: Microsoft Senior Security Researcher Mor Rubin talked about new research about a mechanism designed to allow authentication between Microsoft Azure Active Directory-joined machines. Mor also explored the foundation of the new network protocol, presented a way (and a tool) to perform pass-the-certificate attacks, and talked through an open-source solution that can help companies hunt for attacks.
  • “CastGuard: Mitigating Type Confusion in C++”: Microsoft Software Security Engineer Joe Bialek discussed type confusion vulnerabilities, which have incredibly powerful primitives to exploit writers. Joe introduced a new mitigation called CastGuard that’s being deployed to a set of Windows components (with more in the works). With a tiny instruction sequence and the virtual function table pointer of an object, CastGuard helps prevent illegal static down-casts in C++ code.
  • Malware Classification With Machine Learning Enhanced by Windows Kernel Emulation”: Microsoft Security Software Engineer Dmitrijs Trizna presented a hybrid machine learning architecture that combines static and dynamic malware analysis methodologies. This architecture surpasses the capabilities of the modern AI classifiers and records a detection rate of 96.7 percent with a fixed false positive rate of 0.1 percent.

Conference social events

It wouldn’t be a conference without plenty of fun social events to get everyone chatting, networking, and celebrating the achievements of security professionals. At the Cybersecurity Women of the Year Awards (CSWY Awards) on August 9, 2022, attendees gathered at the Luxor, enjoyed a gourmet meal, and toasted to female cybersecurity and privacy leaders who are changing the world.

Aanchal Gupta, CVP of Engineering at Microsoft is announcing a winner.

“The CSWY Awards recognize women protecting businesses, schools, and governments from cyber threats actors,” said Carmen Marsh, creator of the CSWY Awards. “We give security pros the opportunity to talk about what’s happening or not happening in cybersecurity and how to make it better. It’s wonderful to bring women from around the world to Las Vegas for this important event while creating inspiring role models for the new generation of cybersecurity professionals.”

As a Signature Sponsor, Microsoft was honored to recognize three barrier breakers serving as role models for future generations of cybersecurity professionals. Microsoft Corporate Vice President of Cloud and Microsoft 365 Security, Aanchal Gupta gave out the Cybersecurity Woman Privacy Woman Law Professional of the Year 2022 award, while Microsoft Senior Director of Security Narrative and Strategy, Shelli Strand awarded the Cybersecurity Woman Influencer of the Year 2022 award. Abhilasha Bhargav-Spantzel, Microsoft Partner Security Architect, gave out the Cybersecurity Woman Volunteer of the Year award.

After dinner and the awards ceremony, attendees networked and danced to a DJ spinning hits.

“Today, we have an incredible opportunity to attract a talented and impassioned generation of defenders and to change the deep gender disparity in our industry. I am so grateful to the Cybersecurity Woman of the Year program organizers for spotlighting the amazing work being done by those superheroes who are setting a powerful example for us all,” said Vasu Jakkal, Microsoft Corporate Vice President of Security, Compliance, Identity, Management, and Privacy, “Microsoft is proud to take part in an event that is helping to cultivate inclusivity, inspire and facilitate mentorship, and celebrate the important field of cybersecurity.”

On August 10, 2022, Microsoft Security Response Center (MSRC) hosted Microsoft’s annual Researcher Celebration event at the Illuminarium in Las Vegas, Nevada. The event brought together some of Microsoft’s Most Valuable Researchers (MVRs), and many security leaders and professionals. Attendees met with the head of MSRC, Aanchal Gupta, MSRC leadership, and other key Microsoft attendees to thank the MVRs and researcher community for their contributions. Check out the list of MSRC 2022 Most Valuable Researchers!

Throughout the evening, more than 500 guests from more than 200 organizations across the information security community participated in space-themed activities and experiences while connecting and re-connecting in person for the first time in many years. Thanks to everyone that attended and helped make the event memorable.

Collage of images showing people at the different experiences at Microsoft’s annual Researcher Celebration event at the Illuminarium in Las Vegas.

More threat intelligence resources

We can’t wait for future opportunities to connect with everyone again in person. Until then, there are a few ways for you to stay connected and up to date on the latest from Microsoft in threat intelligence solutions:

  • Join us on September 15, 2022, for the free digital event Stop Ransomware with Microsoft Security to hear key insights from Microsoft’s leadership, including a fireside conversation between Charlie Bell, Executive Vice President of Microsoft Security, and Vasu Jakkal, Corporate Vice President of Microsoft Security, Compliance, Identity, and Privacy Business.
  • Explore details on Microsoft’s threat intelligence solution in our blog post about new solutions for threat intelligence and attack surface management.
  • Check out the latest Cyber Signals report.
  • If you attended Black Hat and interacted with Microsoft, please share your feedback with us. 

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us at @MSFTSecurity for the latest news and updates on cybersecurity.


1Black Hat USA 2022 Closes on a Record Breaking Event in Las Vegas & Online, AP News. August 19, 2022.

The post Microsoft Security highlights from Black Hat USA 2022 appeared first on Microsoft Security Blog.

]]>
Microsoft showcases the future of comprehensive security at RSA 2022 http://approjects.co.za/?big=en-us/security/blog/2022/05/16/microsoft-showcases-the-future-of-comprehensive-security-at-rsa-2022/ Mon, 16 May 2022 16:00:00 +0000 RSA 2022 is happening in person—find out about Microsoft-sponsored sessions, pre-day events, speakers, awards, and more.

The post Microsoft showcases the future of comprehensive security at RSA 2022 appeared first on Microsoft Security Blog.

]]>
The last time the RSA Conference was held as an in-person event was in 2020. Needless to say, a lot has changed since then. RSA is once again going forward as an in-person (and digital) event in San Francisco, from June 6 to 9, 2022. After two years of remote interactions, we’re excited to exchange ideas with industry influencers and security professionals from across North America. Microsoft Security will be onsite at booth 6059 at Moscone Center with 1,500 square feet of Microsoft and partner-led demonstrations from Nuance, Rubrik, Wipro, and Veritas. There will also be 40 theater sessions, including presentations from Entrust, Lighthouse, Open Systems, Vectra AI, and Yubico covering the companies’ newest Microsoft product integrations—topics include threat protection, identity and access management, endpoint security, and Zero Trust.

Microsoft will also be part of more than 20 earned sessions at the RSA Conference. We’ll also be showcasing new innovations that extend Microsoft’s vision for comprehensive end-to-end security, along with a special keynote address by Vasu Jakkal, Corporate Vice President (CVP) of Microsoft Security, Compliance, Identity, and Management. You won’t want to miss our launch party and immersive experience at the Microsoft Security Hub at Bespoke Westfield Event Center, as well as hybrid cloud security workshops and special art installations. Start planning your trip now—you don’t want to miss this.

Microsoft Security Hub—You’re invited

We’re so excited to be onsite this year that we’re kicking things off early. Join us on June 5, 2022, from 2 PM to 9 PM Pacific Time (PT) at Microsoft Security Hub at Bespoke Westfield Event Center for a special Microsoft Security pre-day event. Featured speakers will be Vasu Jakkal, CVP of Microsoft Security, Bret Arsenault, CVP and Chief Information Security Officer (CISO), and Joy Chik, CVP of Identity and Access.

Along with meeting old friends and making new connections, participants are welcome to:

  • Join in Q&As with Microsoft security experts about Zero Trust, threat intelligence, multicloud protection, and risk management.
  • Learn how Microsoft is re-envisioning the future of identity and access for our increasingly digital world.
  • Gain insights on how to safeguard your people, data, and infrastructure with the most comprehensive detection, protection, and response capabilities for all devices and endpoints.
  • Discover best practices on how to actively manage your data estate, mitigate risk, and assess compliance to safeguard personal data and build a privacy-resilient workplace.
  • Participate in an immersive walkthrough experience ending with a custom swag bar.
  • Network with other security professionals at our rooftop reception following the event.

The Microsoft Security Hub will also host the Microsoft Security Party, Microsoft Security Experts interactive experience, as well as an Innovation Zone, listening sessions, executive lunches, CISO Roundtable, MISA meeting room, tours, and dazzling visual art installations. And of course, happy hours!

Microsoft keynote and sponsored sessions

Microsoft will participate in more than 20 earned sessions spanning supply chain attacks, evolving regulations, Zero Trust security, public and private partnerships, ransomware challenges, securing multicloud environments, decentralized identity, IoT security, and other topics. Session speakers include Christopher Young, Executive Vice President Business Development, Strategy and Ventures; Amy Hogan-Burney, General Manager of the Digital Crimes Unit/Associate General Counsel; Edna Conway, Vice President (VP), Security and Risk Officer, Azure Hardware Systems and Infrastructure; Julie Brill, Chief Privacy Officer and CVP for Global Privacy and Regulatory Affairs; Aanchal Gupta, VP, Azure Security; Jessica Payne, Principal Security Research; Balaji Parimi, Partner General Manager; Summer Frederickson, Principal Program Manager, Security Intelligence and Engineering; and more.

Highlighted sessions

Keynote: Innovation, Ingenuity, and Inclusivity: The Future of Security is Now
Speaker: Vasu Jakkal, CVP, Microsoft Security
Location: West Stage, Moscone West Level 1
Date/Time: Tuesday, June 7, 2022 | 3:35 PM to 3:55 PM PT
Synopsis: What lies ahead in cybersecurity is a brave new world—sophisticated threats, everything connected, and real human life at stake. Securing our future will require transformative thinking in technology, human expertise, and growing our defender community. Join Vasu Jakkal, Microsoft CVP of Security, Compliance, Identity, and Management for a look at where security is heading, and what we’ll need to get there.

Sponsored Breakfast Session: Deep dive in multicloud permissions management ​
Speakers: Balaji Parimi, Partner General Manager
Location: Briefing Center, South Expo
Date/Time: Wednesday, June 8, 2022 | 7:30 AM to 8:15 AM PT
Synopsis: Join us in this demo-heavy session to learn more about Microsoft’s multicloud permissions management solution and our latest innovations in multicloud and privileged access management.

Sponsored Track Session: Practical Learnings for Threat Hunting and Improving Your Security Posture ​
Speakers: Jessica Payne, Principal Security Research ​
Location: TBD
Date/Time: Wednesday, June 8, 2022 | 9:40 AM to 10:30 AM PT
Synopsis: Understanding the threat landscape is crucial to managing your security posture. A Microsoft Threat Intelligence Strategist will discuss threat hunting and improving your security posture from a threat intelligence-informed perspective. You’ll also get real-world input from a customer case study on securing a complex network.​

Microsoft Security Excellence Awards

The Microsoft Intelligent Security Association (MISA) is a coalition of over 300 independent software vendors and managed security service providers that have integrated their solutions to defend against evolving threats. To kick off our action-packed week at this year’s RSA Conference, we’re proud to host the live, in-person Microsoft Security Excellence Awards 2022, on Sunday, June 5, 2022. MISA members will enjoy an exclusive evening of entertainment, drinks, and hors d’oeuvres, with their Excellence Awards presented by Microsoft Security leadership. The ceremony will recognize MISA members’ accomplishments by celebrating their successes across 10 finalist fields, including Compliance and Identity Trailblazer, Zero Trust Champion, and Security Changemaker. It’s sure to be a night to remember.

Helping you move forward—fearless

At Microsoft Security, we’re committed to helping organizations protect their networks, data, employees, and customers by providing comprehensive security across devices, identities, and apps—even on third-party clouds and platforms. We know we can’t do it alone; so we’re looking forward to hearing your insights and feedback at RSA 2022. Remember to register for the Microsoft Security pre-day event at Bespoke Event Center, Westfield Mall, 845 Market St. San Francisco, CA 94103(dedicated entrance on Market Street). We’ll see you there!

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us at @MSFTSecurity for the latest news and updates on cybersecurity.

The post Microsoft showcases the future of comprehensive security at RSA 2022 appeared first on Microsoft Security Blog.

]]>