By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Sécurité Helvétique News | AmyrisSécurité Helvétique News | AmyrisSécurité Helvétique News | Amyris
  • Home
  • Compliance
    Compliance
    Show More
    Top News
    McDonald’s Delaware Court Decision Will Change CCO World Forever
    21 February 2023
    Health Equity: Board Directors’ Most Important ESG Measure
    7 May 2023
    News Roundup: 75% of US Companies Mention Climate Risk in 10-Ks
    15 June 2024
    Latest News
    Fractured & Fraught — but Still Potentially Profitable: The State of ESG in 2025
    7 November 2025
    UK AML Reform in 2025: A Public Recalibration of Risk and Responsibility
    1 November 2025
    US National Security Compliance Risk & Readiness Report
    26 October 2025
    What Would a Farage Government Mean for Compliance?
    20 October 2025
  • Cyber Security
    Cyber Security
    Show More
    Top News
    Clipper Malware Found in 450+ PyPI Packages!
    24 February 2023
    SysUpdate Malware Strikes Again with Linux Version and New Evasion Tactics
    2 March 2023
    New Critical Flaw in FortiOS and FortiProxy Could Give Hackers Remote Access
    9 March 2023
    Latest News
    North Korean Hackers Target Developers with Malicious npm Packages
    30 August 2024
    Russian Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack
    29 August 2024
    Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32
    29 August 2024
    2.5 Million Reward Offered For Cyber Criminal Linked To Notorious Angler Exploit Kit
    29 August 2024
  • Technology
    Technology
    Show More
    Top News
    Get Microsoft Office for Windows for life for $54, plus bonus finance courses
    26 February 2023
    Google Doodle Celebrates Mutual Support for International Women’s Day
    8 March 2023
    Extrapolations: the real science behind Apple’s climate change drama
    17 March 2023
    Latest News
    Why XSS still matters: MSRC’s perspective on a 25-year-old threat  | MSRC Blog
    9 September 2025
    Microsoft Bug Bounty Program Year in Review: $13.8M in Rewards | MSRC Blog
    28 August 2025
    Microsoft Bounty Program Year in Review: $16.6M in Rewards  | MSRC Blog
    27 August 2025
    postMessaged and Compromised | MSRC Blog
    26 August 2025
  • Businness
    Businness
    Show More
    Top News
    Oil rally cools as markets weigh OPEC+ cut, manufacturing slowdown By Investing.com
    4 April 2023
    U.S. to finalize rule to limit asylum access at Mexico border by May 11 By Reuters
    6 May 2023
    NFLX, CRWD, PYPL, JNPR and more
    9 January 2024
    Latest News
    US Supreme Court lets Trump withhold $4 billion in food aid funding for now
    8 November 2025
    Client Challenge
    7 November 2025
    WeRide CEO pitches robotaxi safety as shares start trading in HK
    6 November 2025
    Naver reports record Q3 earnings on AI-driven growth
    5 November 2025
  • ÉmissionN
    Émission
    Cyber Security Podcasts
    Show More
    Top News
    Stream episode Cybercrime Wire For Mar. 10, 2023. Cyberattack On Parques Reunidos Group. WCYB Digital Radio. by Cybercrime Magazine podcast
    12 March 2023
    How To Report A Cybercrime In Delaware or Anywhere in the U.S.
    20 March 2023
    Stream episode Evolving Threat Insights. Post-Quantum Cryptography Threats. Peter Bordow & Dale Miller, Wells Fargo by Cybercrime Magazine podcast
    28 March 2023
    Latest News
    Stream episode Cybercrime Magazine Update: Cybercrime In India. Sheer Volume Overwhelming Police Forces. by Cybercrime Magazine podcast
    3 March 2025
    Autonomous SOC. Why It’s A Breakthrough For The Mid-Market. Subo Guha, SVP of Product, Stellar Cyber
    2 March 2025
    Cyber Safety. Protecting Families From Smart Toy Risks. Scott Schober, Author, "Hacked Again."
    2 March 2025
    Cybercrime News For Feb. 25, 2025. Hackers Steal $49M from Infini Crypto Fintech. WCYB Digital Radio
    2 March 2025
Search
Cyber Security
  • Application Security
  • Darknet
  • Data Protection
  • network vulnerability
  • Pentesting
Compliance
  • LPD
  • RGPD
  • Finance
  • Medical
Technology
  • AI
  • MICROSOFT
  • VERACODE
  • CHECKMARKX
  • WITHSECURE
  • Amyris
  • Contact
  • Disclaimer
  • Privacy Policy
  • About us
© 2023 Sécurité Helvétique NEWS par Amyris Sarl. Tous droits réservés
Reading: Concluding the Azure Sphere Security Research Challenge, Microsoft Awards $374,300 to Global Security Research Community | MSRC Blog
Share
Sign In
Notification Show More
Font ResizerAa
Sécurité Helvétique News | AmyrisSécurité Helvétique News | Amyris
Font ResizerAa
  • Home
  • Compliance
  • Cyber Security
  • Technology
  • Business
Search
  • Home
    • Compliance
    • Cyber Security
    • Technology
    • Businness
  • Legal Docs
    • Contact us
    • Disclaimer
    • Privacy Policy
    • About us
Have an existing account? Sign In
Follow US
  • Amyris
  • Contact
  • Disclaimer
  • Privacy Policy
  • About us
© 2023 Sécurité Helvétique par Amyris Sarl.
Sécurité Helvétique News | Amyris > Blog > Application Security > Concluding the Azure Sphere Security Research Challenge, Microsoft Awards $374,300 to Global Security Research Community | MSRC Blog
Application SecurityBackup and recoveryData securityDevice SecurityMICROSOFTNetwork securitynetwork vulnerabilityTechnology

Concluding the Azure Sphere Security Research Challenge, Microsoft Awards $374,300 to Global Security Research Community | MSRC Blog

webmaster
Last updated: 2024/01/08 at 1:44 AM
webmaster
Share
5 Min Read
SHARE

The Azure Sphere Security Research Challenge brought together 70 researchers from 21 countries to help secure Azure Sphere customers and expand Microsoft’s partnerships with the global IoT security research community. During the three-month Azure Sphere Security Research Challenge, researchers surfaced 20 Critical or Important severity security vulnerabilities, with Microsoft awarding $374,300 in bounty awards for 16 bounty eligible reports.

Total Reports Received: 40 Reports Led to Improvements: 30 Critical/Important Reports: 20 Bounty Eligible Reports: 16 Total Bounty Awards: $374,300

Many of the vulnerabilities found during the research challenge were novel and high impact, and led to major security improvements for Azure Sphere in their 20.07, 20.08 and the latest 20.09 updates, which have been automatically pushed to Azure Sphere devices that are connected to the internet to help secure Azure Sphere customers. Security researchers from McAfee ATR and Cisco Talos reported some of the highest impact vulnerabilities in Azure Sphere, especially a full attack chain developed by McAfee ATR that exposed a weakness in the cloud and multiple weaknesses on the device including a previously unknown Linux kernel vulnerability.

To focus research in the highest impact areas, we introduced two high priority research scenarios focused on the core of the Azure Sphere OS with $100,000 awards, and six general scenarios focused on various levels of the Azure Sphere OS with up to 20% additional awards on top of the Azure Bounty Program awards. Participating researchers shared disclosures that successfully achieved three of the general scenarios:

  • Anything allowing execution of unsigned code that isn’t pure return oriented programming (ROP) under Linux
  • Anything allowing elevation of privilege outside of the capabilities described in the application manifest (e.g. changing user ID, adding access to a binary)
  • Ability to modify software and configuration options (except full device reset) on a device in the manufacturing state DeviceCompletewhen claimed to a tenant you are not signed into and have no saved capabilities for

Check out the Azure Sphere team’s blog Why we invite security researchers to hack Azure Sphere for more details on the research challenge results and security improvements. Microsoft is also working on assigning CVEs to vulnerabilities found in Azure Sphere, the documentation for which will be released on Update Tuesdays.

We are excited to see the great results from this research challenge and to learn from the program participants’ experiences. This was our first expansion of the Azure Security Lab, an experiment to provide researchers with additional resources to help spark new, high impact research, and develop close collaboration between the security research community and the Microsoft engineering teams through weekly office hours and opportunities for direct collaboration. We strongly believe that this challenge and upcoming expansions of the Azure Security Lab will help to continue to protect our cloud and Azure Sphere, and we look forward to expanding the resources available to security researchers to support high impact research. Future research challenges will be published on our Azure Security Lab program page, stay tuned!

We continue to invite researchers to hunt for high impact vulnerabilities in Azure Sphere as part of our Microsoft Azure Bounty Program. Qualified submissions are eligible for awards up to $40,000 USD.

Special Thanks to Security Researchers and Industry Partners

We believe our partnership with the global security research community is crucial for keeping our customers secure. We are humbled to have the opportunity working with so many talented researchers and industry partners through Coordinated Vulnerability Disclosure in making Azure Sphere and the broader IoT ecosystem more secure.

We appreciate the collaboration in this research challenge with the global security research community, and our key industry partners including Avira, Baidu International Technology, Bitdefender, Bugcrowd, Cisco Systems Inc (Talos), ESET, FireEye, F-Secure Corporation, HackerOne, K7 Computing, McAfee, Palo Alto Networks and Zscaler.

Sylvie Liu & Lynn Miyashita, Security Program Manager, Microsoft Security Response Center

You Might Also Like

This Week in Scams: Fake Steaks and Debit Card Porch Pirates

Understanding prompt injections: a frontier security challenge

AI progress and recommendations

Introducing the Teen Safety Blueprint

From Pilot to Practice: How BBVA Is Scaling AI Across the Organization

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Whatsapp Whatsapp LinkedIn Reddit Telegram Email Copy Link Print
Share
Previous Article Security into industrial and IoT applications
Next Article Secure Download Firmware Update (DFU)
Leave a comment Leave a comment

Comments (0) Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
11.6k Followers Pin
56.4k Followers Follow
136k Subscribers Subscribe
4.4k Followers Follow
- Advertisement -
Ad imageAd image

Latest News

From Prompt Injection To Account Takeover · Embrace The Red
Pentesting 8 November 2025
This Week in Scams: Fake Steaks and Debit Card Porch Pirates
network vulnerability 8 November 2025
Gotthard Pass to close on Friday
SWITZERLAND 8 November 2025
From Prompt Injection To Account Takeover · Embrace The Red
Pentesting 8 November 2025
//

We influence 20 million users and is the number one business and technology news network on the planet

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

Loading
Sécurité Helvétique News | AmyrisSécurité Helvétique News | Amyris
Follow US
© 2023 Sécurité Helvétique NEWS par Amyris Sarl. Tous droits réservés
Amyris news letter
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

Loading
Zero spam, Unsubscribe at any time.
login Amyris SH
Welcome Back!

Sign in to your account

Lost your password?