Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

8/5/2019
01:45 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Microsoft Opens Azure Security Lab, Raises Top Azure Bounty to $40K

Microsoft has invited security experts to 'come and do their worst' to mimic cybercriminals in the Azure Security Lab.

BLACK HAT USA 2019 – Las Vegas – Microsoft today launched the Azure Security Lab and doubled its top Azure bug-bounty reward in an effort to further strengthen cloud security.

The Azure Security Lab is a set of dedicated cloud hosts designed for security researchers to test attacks against infrastructure-as-a-service (IaaS) scenarios while isolated from Azure customers. This isolation protects the Azure framework from malicious activity and gives approved researchers a place to analyze, and an attempt to exploit, the vulnerabilities they find in Azure.

Microsoft wants security experts to "confidently and aggressively test Azure," and it has already invited a group of hackers to "come and do their worst" to emulate cybercriminals in the lab.

Due to the limited number of hosts, security pros who want to participate in the Azure Security Lab must apply. Accepted researchers will have access to quarterly campaigns for targeted scenarios, regular recognition, and exclusive swag, writes Microsoft's principal security PM manager, Kymberlee Price, in a blog post. In addition to a secure testing space, the lab will let researchers work with Azure security experts as they explore vulnerabilities in the cloud.

Scenario-based challenges in the Azure Security Lab give researchers an opportunity to earn awards up to $300,000. The top-paying scenario is a virtual machine escape, in which researchers can demonstrate a functional exploit enabling an escape from a guest virtual machine to a host or to another guest VM. Demonstration of denial of service to the Azure host will earn $50,000.

In other incentive-related news, Microsoft is doubling its top bounty reward for Azure bugs to $40,000 as part of the Azure Bounty Program, which offers rewards from $500 to $40,000. In total, the company has paid out $4.4 million in bounty rewards over the past 12 months.

Microsoft today also formalized its two-decade commitment to the principle of Safe Harbor, Price adds. This initiative lets security experts pursue vulnerability research and report the problems they find without worrying about legal consequences.

Related Content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15037
PUBLISHED: 2020-07-07
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.
CVE-2019-4323
PUBLISHED: 2020-07-07
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
CVE-2019-4324
PUBLISHED: 2020-07-07
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
CVE-2020-15036
PUBLISHED: 2020-07-07
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Linked.php dv parameter.
CVE-2020-15577
PUBLISHED: 2020-07-07
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Cameralyzer allows attackers to write files to the SD card. The Samsung ID is SVE-2020-16830 (July 2020).