Microsoft Launches Bounty Program for IoT Bugs - RTInsights

Microsoft Launches Bounty Program for IoT Bugs

Microsoft Launches Bounty Program for IoT Bugs

Penetration into a computer of a virus from Internet

The company is offering a $100,000 bounty to anyone who can break into Azure Sphere.

Written By
Sue Walsh
Sue Walsh
May 25, 2020

As it works to enhance the security of its IoT products, Microsoft has offered a $100,000 bug bounty to ethical hackers who can break into Azure Sphere.

This latest Sphere Security Research Challenge lets the bug hunters communicate directly with the company’s technical team during their attempted break-ins.

Three parts comprise Microsoft Sphere:

  • Sphere OS, a custom version of Linux created by Microsoft
  • Custom silicon produced by the company’s partners including MediaTek, NXP, and Qualcomm
  • A security service that runs in the Azure cloud

Microsoft has offered two $100,000 prizes in its latest hacking challenge. The company will award the first prize to the first successful hacker to infiltrate Plutron — a security subsystem that provides a root of trust to the Sphere microcontroller — and execute code. The system runs a secure boot process that loads select software components before providing runtime services.

The first hacker who infiltrates Secure World and runs code wins the second prize. One of Sphere’s operating modes, the tightly locked down Secure World only permits Microsoft-written code to run. A security monitor protects sensitive hardware like memory and controls access to Pluton.

Contestants must adhere to certain conditions, like not physically attacking the device. Microsoft will also award lower payouts for other attacks that fall under its existing Azure bug bounty program, with bonus payments up to 20%. Qualifying attacks include:

  • Running code on networks (a Linux networking daemon)
  • Spoofing device authentication
  • Unexpected elevation of privilege
  • Altering software and configuration options that you’re not supposed to, or alter the firewall built into the microprocessor hardware and cause a Sphere device to communicate with an unauthorized destination

The challenge will run from June 1 to August 31, 2020.

Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

Powering Smart Cities: Designing Rugged PoE for Outdoor and Industrial Edge Deployments
Jordan Smith
Apr 2, 2026
Securing Time Synchronization: The Overlooked Control in Modern Cybersecurity
Liz Ticong
Apr 2, 2026
Why Satellite Connectivity Sits at the Heart of Enterprise Network Resilience
Fánan Henriques
Feb 14, 2026
Real-time Analytics News for the Week Ending January 31

Featured Resources from Cloud Data Insights

The RAG Pipeline Nobody Told You Was Unnecessary
Avi Cavale
Apr 8, 2026
Which is Right for Your Organization: Business Intelligence or Operational Intelligence?
Marc Stevens
Apr 7, 2026
Minimus Appoints Tech Dealmaker Yael Nardi as Chief Business Officer to Drive Hyper-Growth
TechnologyWire
Apr 7, 2026
Why High Availability at the Edge Is the Next Frontier for SQL Server
Don Boxley Jr.
Apr 7, 2026
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.