Breaking News

Sony Expands Its Turntable Lineup with New Wireless Models ENDORFY introduces Atlas Electric desks Sony Unveils LinkBuds Clip Open Earbuds be quiet! enters high-end gaming mouse market with Dark Perk Ergo and Dark Perk Sym ASUS ROG announces ROG Strix GS-BE7200 Dual-Band WiFi 7 Gaming Router

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft Launches $250,000 Security Bounty

Microsoft Launches $250,000 Security Bounty

Enterprise & IT Mar 15,2018 0

Microsoft is launching a limited-time bounty program for speculative execution side channel vulnerabilities - bugs that are similar to the Meltdown and Spectre CPU flaws.

This new class of vulnerabilities was disclosed in January 2018 and represented a major advancement in the research in this field. Microsoft is launching a bounty program to encourage research into the new class of vulnerability and the mitigations Microsoft has put in place to help mitigate this class of issues.

The bounty will be open until December 31, 2018. Bounty Tiers:

Tier  Payout (USD)
Tier 1: New categories of speculative execution attacks  Up to $250,000
Tier 2: Azure speculative execution mitigation bypass  Up to $200,000
Tier 3: Windows speculative execution mitigation bypass  Up to $200,000
Tier 4: Instance of a known speculative execution vulnerability (such as CVE-2017-5753) in Windows 10 or Microsoft Edge. This vulnerability must enable the disclosure of sensitive information across a trust boundary  Up to $25,000

Tier 1 focuses on new categories of attacks involving speculative execution side channels. Microsoft's Security Research & Defense team has published a blog with additional information.

Tiers 2 and 3 focus on identifying possible bypasses for mitigations that have been added to Windows and Azure to defend against the attacks that have been identified. Tier 4 covers exploitable instances of CVE-2017-5753 or CVE-2017-5715 that may exist.

Microsoft says it will share, under the principles of coordinated vulnerability disclosure, the research disclosed to them under this program so that affected parties can collaborate on solutions to these vulnerabilities.

Tags: malware
Previous Post
U.S. Sanctions Russian Cyber Actors for Cyber-Attacks
Next Post
Intel to Bring Hardware-based Protection to Data Center and PC Processors

Related Posts

  • Intel and Microsoft Convert Malware to Images to Spot Threads Faster

  • Malwarebytes Outlines Coronavirus Scams

  • Google's AI Tool Scans Billions of Gmail Attachments to Secure Inboxes

  • Pentagon, DHS And FBI Issued New Malware Warning For Windows Users

  • Lazarus Group Targets Linux With New Malware

  • Hackers Targeted Government Officials Using WhatsApp Malware

  • Malware Masked as Textbooks and Essays

  • Samsung Laptop Full of Notorious Malware Is On Sale For $1.2M

Latest News

Sony Expands Its Turntable Lineup with New Wireless Models
Consumer Electronics

Sony Expands Its Turntable Lineup with New Wireless Models

ENDORFY introduces Atlas Electric desks
Gadgets

ENDORFY introduces Atlas Electric desks

Sony Unveils LinkBuds Clip Open Earbuds
Consumer Electronics

Sony Unveils LinkBuds Clip Open Earbuds

be quiet! enters high-end gaming mouse market with Dark Perk Ergo and Dark Perk Sym
Gaming

be quiet! enters high-end gaming mouse market with Dark Perk Ergo and Dark Perk Sym

ASUS ROG announces ROG Strix GS-BE7200 Dual-Band WiFi 7 Gaming Router
Enterprise & IT

ASUS ROG announces ROG Strix GS-BE7200 Dual-Band WiFi 7 Gaming Router

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed