Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

8/5/2019
01:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Microsoft Opens Azure Security Lab, Raises Top Azure Bounty to $40K

Microsoft has invited security experts to 'come and do their worst' to mimic cybercriminals in the Azure Security Lab.

BLACK HAT USA 2019 – Las Vegas – Microsoft today launched the Azure Security Lab and doubled its top Azure bug-bounty reward in an effort to further strengthen cloud security.

The Azure Security Lab is a set of dedicated cloud hosts designed for security researchers to test attacks against infrastructure-as-a-service (IaaS) scenarios while isolated from Azure customers. This isolation protects the Azure framework from malicious activity and gives approved researchers a place to analyze, and an attempt to exploit, the vulnerabilities they find in Azure.

Microsoft wants security experts to "confidently and aggressively test Azure," and it has already invited a group of hackers to "come and do their worst" to emulate cybercriminals in the lab.

Due to the limited number of hosts, security pros who want to participate in the Azure Security Lab must apply. Accepted researchers will have access to quarterly campaigns for targeted scenarios, regular recognition, and exclusive swag, writes Microsoft's principal security PM manager, Kymberlee Price, in a blog post. In addition to a secure testing space, the lab will let researchers work with Azure security experts as they explore vulnerabilities in the cloud.

Scenario-based challenges in the Azure Security Lab give researchers an opportunity to earn awards up to $300,000. The top-paying scenario is a virtual machine escape, in which researchers can demonstrate a functional exploit enabling an escape from a guest virtual machine to a host or to another guest VM. Demonstration of denial of service to the Azure host will earn $50,000.

In other incentive-related news, Microsoft is doubling its top bounty reward for Azure bugs to $40,000 as part of the Azure Bounty Program, which offers rewards from $500 to $40,000. In total, the company has paid out $4.4 million in bounty rewards over the past 12 months.

Microsoft today also formalized its two-decade commitment to the principle of Safe Harbor, Price adds. This initiative lets security experts pursue vulnerability research and report the problems they find without worrying about legal consequences.

Related Content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/30/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27652
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27653
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27654
PUBLISHED: 2020-10-29
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
CVE-2020-27655
PUBLISHED: 2020-10-29
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
CVE-2020-27656
PUBLISHED: 2020-10-29
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.