Microsoft has awarded over $370,000 in bug bounties to security researchers for vulnerability reports submitted through the Azure Sphere Security Research Challenge (ASSRC) IoT-focused research program. The Azure Sphere Security Research Challenge is a 3-month extension of the Azure Security Lab bounty program that Microsoft announced at Black Hat 2019.
The ASSRC expansion added to the already existing incentives, coordination framework, and support resources to make Coordinated Vulnerability Disclosure (CVD) easier for researchers and further encourage Azure Sphere research.

As BleepingComputer reports, 70 researchers from more than 20 countries submitted 40 vulnerability reports from June 1, 2020, to August 31, 2020, with 30 of these reports leading to improvements to the Azure Sphere IoT security solution
Microsoft has awarded money as a reward to researchers who were able to demonstrate their ability to execute code in the Secure World of the Azure Sphere application platform or in the Microsoft Pluton security subsystem.

Additionally, the tech giant said that many of the vulnerabilities identified during the research challenge were novel and high-impact, leading to significant security improvements for Azure Sphere in 20.07, 20.08, and the latest updates , which have been automatically pushed to devices connected to the Internet, to safeguard Azure Sphere customers and expand Microsoft's partnerships with the global IoT security research community.
The company also added that security researchers from McAfee ATR and Cisco Talos reported some of the highest-impact vulnerabilities in Azure Sphere, including a full-scale attack developed by McAfee ATR that exposed a vulnerability in the cloud and multiple vulnerabilities on the device, including a previously unknown vulnerability in the Linux.

Researchers participating in the challenge achieved three of the general scenarios focused on various layers of the Azure Sphere operating system:
- Anything that allows unsigned code that is not pure ROP (Return Oriented Programming) under Linux.
- Anything that allows privilege escalation outside of the capabilities described in the application declaration (e.g. changing user ID, adding access to binary).
- Ability to modify software and configuration options (except for a full device reset) on a device in manufacturing mode.
Researchers can also submit reports of any high-impact vulnerabilities in Azure Sphere as part of the Microsoft Azure bounty program, with the best reports eligible for prizes of up to $40,000.
Microsoft announced in August that it has awarded $13.7 million to researchers who reported vulnerabilities in the past 12 months through 15 bug bounty programs, between July 1, 2019, and June 30, 2020. In 2020 alone, the company ran six new bug bounty programs and two new research grants, receiving 1,226 vulnerability reports from 327 security researchers. Finally, Microsoft also joined the Open Source Security Foundation (OpenSSF) as a founding member in August, along with GitHub, Google, IBM, JPMC, NCC Group, OWASP Foundation, and Red Hat.
