Microsoft paid $374,300 to experts as part of the Azure Sphere cybersecurity research

Microsoft paid $374,300 to experts as part of the Azure Sphere cybersecurity research

Microsoft awarded $374,300 to security researchers as part of the Azure Sphere Security Research Challenge, which lasted three months. During the research, experts were able to identify 20 critical security vulnerabilities that were addressed in the updates 20.07, 20.08, and 20.09. A total of 70 researchers from 21 countries participated in the contest.

Microsoft paid $374,300 to experts as part of the Azure Sphere cybersecurity research

As part of the study, Microsoft invited leading global cybersecurity experts and security solution providers to attempt to hack devices using attack methods commonly employed by malicious actors. Contest participants were provided with a development kit, direct communication with the OS security team, email support, and publicly available operating system kernel code.

The contest aimed to draw researchers' attention to what has the greatest impact on customer security. Therefore, experts were provided with six research scenarios with an additional reward of up to 20% over the standard reward in the Azure Bounty program (up to $40,000), as well as $100,000 for two high-priority scenarios.

Several participants helped uncover potentially dangerous vulnerabilities in Azure Sphere. A total of 40 submissions were received during the contest, 30 of which led to product improvements. Sixteen of these earned a reward, totaling $374,300.

The research was conducted in partnership with companies such as Avira, Baidu International Technology, Bitdefender, Bugcrowd, Cisco Systems Inc (Talos), ESET, FireEye, F-Secure Corporation, HackerOne, K7 Computing, McAfee, Palo Alto Networks, and Zscaler.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster