HomeSecurityMicrosoft: Announces bug bounty program for Defender

Microsoft: Announces bug bounty program for Defender

Microsoft has launched a new bug bounty program for its Microsoft Defender security platform . Participants will be rewarded with rewards ranging from $ 500 to $20,000.

Microsoft bug bounty

A higher reward could be available, but Microsoft will determine the final amount based on the severity and impact of the vulnerability and the quality of the submission . The highest reward is available for high-quality reports of remote code execution vulnerabilities that are very severe (critical).

Currently, the Microsoft Defender bug bounty program is limited in scope and will focus exclusively on Microsoft Defender for Endpoint APIs (Application Programming Interfaces). However, it is expected to expand to include other Defender products in the future

See also: HackerOne: Has given away over $300 million in bug bounty programs

“The Microsoft Defender Bounty Program invites researchers from around the world to identify vulnerabilities in Defender products and services and share them with our team,” said MSRC Senior Program Manager Madeline Eckert.

“Microsoft's Bug Bounty programs represent one of the many ways we invest in partnerships with the global security to help keep Microsoft customers safe.“.

The full list of vulnerabilities that researchers need to find:

  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • Server-side request forgery (SSRF)
  • Cross-tenant data tampering or access
  • Insecure direct object references
  • Insecure deserialization
  • Injection vulnerabilities
  • Server-side code execution
  • Significant security misconfiguration (when not caused by the user)
  • Use of components with known vulnerabilities (requires full proof of concept (PoC) for exploitation. For example, simply identifying an out-of-date library does not qualify for a prize).

In case multiple researchers report the same bug, the reward will go to the one who submitted it first.

See also: Google expands bug bounty program for generative AI attacks

Additionally, if a submission meets the criteria for multiple bounty programs, researchers will receive the highest reward from a single program . More details about the Microsoft Bug Bounty Program can be found here.

Microsoft revealed that it paid $58.9 million in rewards to 1,147 security researchers worldwide who reported 446 vulnerabilities in 22 bug bounty programs.

Microsoft Defender

A month earlier, the company announced a new AI bounty program, focused on the AI-powered Bing experience

Bug bounty programs contribute to cybersecurity by providing an additional line of defense against cyberattacks. Security professionals and the research community can exploit weaknesses in systems and report vulnerabilities to companies. This allows organizations to identify and fix vulnerabilities before they are exploited by attackers.

Bug bounty programs also play a role in raising awareness about cybersecurity. Through these programs, security researchers can share their knowledge and educate stakeholders about vulnerabilities and security best practices. This leads to increased awareness and better protection of systems from attacks.

See also: Microsoft: New bug bounty program for AI-powered Bing

Additionally, bug bounty programs offer an incentive for security researchers to discover and report vulnerabilities. Through rewards offered to researchers for their findings, bug bounty programs provide a financial incentive to search for vulnerabilities and report them.

Finally, bug bounty programs promote collaboration and knowledge sharing between security researchers and organizations. Researchers can exchange ideas, techniques, and experiences with other researchers and contribute to the development and improvement of security methods. This leads to a continuous evolution and improvement of cybersecurity.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS