1.5K Followers
69 Following
52 Posts
VP OS Security @MSFT || CISA Technical Advisory Committee || Instagram: dwizzzleMSFT

My team just dropped Post-Quantum Cryptography to Windows Insiders and Microsoft Linux!! Yes, it’s open source

https://techcommunity.microsoft.com/blog/microsoft-security-blog/post-quantum-cryptography-comes-to-windows-insiders-and-linux/4413803

Post-Quantum Cryptography Comes to Windows Insiders and Linux | Microsoft Community Hub

Introduction  As the digital landscape continues to evolve, the emergence of quantum computing presents both significant opportunities and challenges....

TECHCOMMUNITY.MICROSOFT.COM
Enhance your application security with administrator protection

Introduction Administrator protection is a new Windows 11 platform security feature that aims to protect the admin users on the device while still allowing them to perform the necessary functions which may require use of admin level permissi

Windows Developer Blog

My blog on how we are securing the agentic era on Windows 11 with MCP support announced at \\BUILD

https://blogs.windows.com/windowsexperience/2025/05/19/securing-the-model-context-protocol-building-a-safer-agentic-future-on-windows/

Securing the Model Context Protocol: Building a safer agentic future on Windows

As AI agents become more capable and integrated into daily workflows, the need for secure, standardized communication between tools and agents has never been greater. At Microsoft Build 2025, we’re announcing an early preview of how Windows 11 is e

Windows Experience Blog
Reaper for ARM64EC is BONKERS efficient on the Snapdragon elite. I've got tons of stuff being emulated and its laughing at my workloads. The fact that i can do an entire track with a surface and no fans is mind blowing. THANK YOU @justin @itanium
My new blog outlining the largest security changed to Windows in a decade.

https://blogs.windows.com/windowsexperience/2024/11/19/windows-security-and-resiliency-protecting-your-business/
Windows security and resiliency: Protecting your business

At Microsoft, security is our top priority, and with every release, Windows becomes even more secure. At Ignite 2024, we will highlight new Windows security innovations that will provide the clarity and confidence our customers and organizations requ

Windows Experience Blog

My new blog - featuring: a technical overview of the CrowdStrike incident, why security products user kernel mode, and what this means for the future of Windows.

https://www.microsoft.com/en-us/security/blog/2024/07/27/windows-security-best-practices-for-integrating-and-managing-security-tools/

Shout outs to my non-Microsoft friends who gave me input and technical editing, appreciate you!

Windows Security best practices for integrating and managing security tools | Microsoft Security Blog

We examine the recent CrowdStrike outage and provide a technical overview of the root cause.

Microsoft Security Blog

[2/2] It is essentially two documents, a discussion of memory safety technologies and then specific CISA recommendations. Also included is a new chart providing the granular root-cause-analysis (RCA) for memory safety issues reported to Microsoft and a great appendix for those wanting more.

I would like to thank everyone who put work in on this. Of the many people who briefed us please reveal yourselves if you wish to be identified.

The TAC: Jeff Moss @thedarktangent Subcommittee Chair, DEF CON Communications. Dino Dai Zovi, CashApp. Luiz Eduardo @effffn, Aruba Threat Labs. Royal Hansen, Google. Isiah Jones, Applied Integrated Technologies. Kurt Opsahl @Kurt, Electronic Frontier Foundation. Stephen Schmidt, Amazon. Yan Shoshitaishvili, Arizona State University. Kevin Tierney, General Motors. Rachel Tobac @racheltobac, SocialProof Security. David Weston @dwizzzle, Microsoft.

From CISA: Eric Goldstein and Bob Lord @boblord

Have the cover just need the album
"[31m"?! ANSI Terminal security in 2023 and finding 10 CVEs: https://dgl.cx/2023/09/ansi-terminal-security - awesome research by @dgl
""?! ANSI Terminal security in 2023 and finding 10 CVEs

Android's security team gave us security partner access where we received the same early notice of vulnerabilities as Android OEMs. Our hope was that we would end up with full partner access. Instead, their business side revoked this and blocked further collaboration with them.