{"id":47715,"date":"2022-08-12T06:30:00","date_gmt":"2022-08-12T06:30:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/47715"},"modified":"2022-08-12T06:30:00","modified_gmt":"2022-08-12T06:30:00","slug":"microsoft-doles-out-13-7m-in-bug-bounties","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=47715","title":{"rendered":"Microsoft doles out $13.7m in bug bounties"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/08\/microsoft-doles-out-13-7m-in-bug-bounties.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p><a href=\"https:\/\/msrc-blog.microsoft.com\/2022\/08\/11\/microsoft-bug-bounty-programs-year-in-review-13-7-in-rewards\/\">Microsoft<\/a> has paid out a total of $13.7m (\u00a311.3m, \u20ac13.3m) in bug bounties over the past 12 months, with 330 researchers from 46 countries acknowledged for their assistance in discovering and reporting a total of 1,091 valid vulnerabilities in Redmond\u2019s products across 17 different <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/bug-bounty-program\">bug bounty programmes<\/a>.<\/p>\n<p>Vulnerabilities in Microsoft\u2019s wares are particularly valuable to threat actors due to the ubiquitous nature of its products in the modern enterprise \u2013 Microsoft frequently finds itself dealing with high-profile incidents such as <a href=\"https:\/\/www.computerweekly.com\/news\/252503494\/Should-I-be-worried-about-PrintNightmare\">PrintNightmare<\/a> or <a href=\"https:\/\/www.computerweekly.com\/news\/252497200\/Emergency-patch-addresses-MS-Exchange-Server-zero-days\">ProxyLogon<\/a>, and its monthly <a href=\"https:\/\/www.computerweekly.com\/news\/252523657\/Microsoft-fixes-two-year-old-MSDT-vulnerability-in-August-update\">Patch Tuesday<\/a> drop is a must-watch event for security professionals.<\/p>\n<p>On this basis, bug bounties paid out by Microsoft tend to be higher, with the average payout made through its programme coming it at $12,000, substantially above the general average of $3,000, as reported by <a href=\"https:\/\/www.hackerone.com\/5th-hacker-powered-security-report\">bug bounty specialist HackerOne<\/a>.<\/p>\n<p>The largest payment made by Microsoft in the past year was a massive $200,000 under the Hyper-V programme, for an undisclosed vulnerability.<\/p>\n<p>Broken out by geography, Microsoft\u2019s data reveal the majority of the ethical hackers working through its programmes are located in China, India and the US, ahead of Australia, Canada, Germany and the UK.<\/p>\n<p>Microsoft\u2019s Lynne Miyashita and Madeline Eckert wrote: \u201cWe believe partnerships with the global security research community are an essential part of protecting customers, and we will continue to invest in and evolve our bounty programmes as a part of strengthening these partnerships. Thank you to all the researchers who shared their research with Microsoft this year to help secure millions of Microsoft customers.\u201d<\/p>\n<p>In the past year, Microsoft has poured focus into evolving its programmes and partnerships in response to the changing threat landscape, they added, particularly as it relates to cloud-based products and services.&nbsp;\u201cA key element of this maturing process is listening to feedback from researchers to remove barriers to entry and better facilitate research efforts,\u201d they said.<\/p>\n<p>\u201cThis year, we introduced a research challenge and new high-impact attack scenarios across many of our programmes to award research focused on the most critical areas to customer security.<\/p>\n<p>\u201cThe addition of these attack scenarios to our Azure, Dynamics 365 and Power Platform, and M365 bounty programmes helps to focus research on the highest impact cloud vulnerabilities including areas like Azure Synapse Analytics, Key Vault, and Azure Kubernetes Services.\u201d<\/p>\n<p>Meanwhile, the high-impact and valuable work of ethical hackers was on display this week at <a href=\"https:\/\/www.blackhat.com\/us-22\/\">Black Hat USA<\/a> in Las Vegas, where crowdsourced bug specialist <a href=\"https:\/\/www.bugcrowd.com\/\">Bugcrowd<\/a> ran its first in-person, live hacking event since the Covid-19 pandemic began, on behalf of <a href=\"https:\/\/uk.indeed.com\/?r=us\">Indeed.com<\/a>, a job-search platform.<\/p>\n<p>Bugcrowd\u2019s Vegas Bug Bash connected Indeed.com with ethical hackers to test out its business-critical attack surfaces and mobile applications, uncovering potentially dangerous security blind spots, and improving testing methodologies at the same time.<\/p>\n<p>Indeed is a long-standing customer of Bugcrowd, and has already rewarded more than 1,500 valid vulnerability submissions. The firm\u2019s chief information security officer (CISO) Anthony Moisant said: \u201cAt Indeed, job seekers and employers alike trust us to protect their information. As we continue rapid growth and product development, we all know that bad actors continue advancing their tactics.<\/p>\n<p>\u201cBy engaging Bugcrowd researchers in this Bug Bash, we\u2019re partnering with good actors to help spot \u2013 and fix \u2013 vulnerabilities to help people get jobs securely.\u201d<\/p>\n<p>\u201cWe are excited about this latest Bug Bash because working in teams showcases the power of human ingenuity, and we want to congratulate Indeed on being a security-first company looking to further ensure their digital assets are secure,&#8221; said&nbsp;Ashish Gupta, Bugcrowd CEO.<\/p>\n<p>\u201cWith the sprawling digitisation of information and assets, and the resulting increase in cyber threats, business leaders need to adopt continuous testing practices that align with their continuous innovation.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has paid out a total of $13.7m (\u00a311.3m, \u20ac13.3m) in bug bounties over the past 12 months, with 330 researchers from 46 countries acknowledged for their assistance in discovering and reporting a total of 1,091 valid vulnerabilities in Redmond\u2019s products across 17 different bug bounty programmes. Vulnerabilities in Microsoft\u2019s wares are particularly valuable to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":47716,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-47715","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/47715","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=47715"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/47715\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/47716"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=47715"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=47715"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=47715"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}