The Verge - Artificial Intelligences 2024年11月19日
Microsoft announces its own Black Hat-like hacking event with big rewards for AI security
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

微软创建实地黑客活动Zero Day Quest,是同类活动中规模最大的。该活动基于现有漏洞赏金计划,鼓励研究影响云与AI软件的安全漏洞。活动今日开始接受研究提交,2025年在微软总部举办。微软还增加AI赏金,提供专家接触机会,并分享漏洞细节以提升安全。此外,微软今日还推出安全管理项目。

🌐微软创建Zero Day Quest,规模最大的实地黑客活动

💻活动基于漏洞赏金计划,研究云与AI安全漏洞

📅今日开始接受提交,2025年在微软总部举办

💰微软加倍AI赏金,提供专家接触机会并分享漏洞细节

🚀今日推出安全管理项目

Illustration by Cath Virginia / The Verge | Photo from Getty Images

Microsoft is creating an in-person hacking event, Zero Day Quest, which it says will be the largest of its kind. The event will build upon Microsoft’s existing bug bounty program, and incentivize research into high-impact security flaws that can affect the software powering cloud and AI workloads.

“This new hacking event will be the largest of its kind, with an additional $4 million in potential awards for research into high-impact areas, specifically cloud and AI,” explains Tom Gallagher, VP of engineering at Microsoft’s security response center. “Zero Day Quest will provide new opportunities for the security community to work hand in hand with Microsoft engineers and security researchers — bringing together the best minds in security to share, learn, and build community as we work to keep everyone safe.”

The Zero Day Quest starts today, with Microsoft accepting submissions for research that is eligible for bounty awards. These submissions will qualify security researchers for a spot at the in-person hacking event at Microsoft’s headquarters in Redmond, Washington in 2025.

Microsoft is doubling the awards that it pays out for AI bounties, and it’s also offering security researchers direct access to Microsoft AI engineers and the company’s AI Red Team — a group of experts that probe Microsoft’s AI systems for failures.

“As part of our ongoing commitment to transparency, we will share the details of the bugs once they are fixed so the whole industry can learn from them — after all, security is a team sport,” says Vasu Jakkal, corporate vice president of security at Microsoft. Any critical vulnerabilities will be shared through the Common Vulnerabilities and Exposures (CVE) program, and Microsoft plans to share any learnings across Microsoft to improve its cloud and AI security.

This new security event comes after Microsoft has embarked on its largest ever security transformation. Microsoft made security its number one priority for every employee earlier this year, following years of security issues and a scathing report from the US Cyber Safety Review Board.

Microsoft Security Exposure Management is also launching today, providing defenders with a graph-based view of a business’ login credentials, permissions, and other security-related elements that can identify potential attack vectors.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

微软 Zero Day Quest 安全漏洞 AI安全 安全管理
相关文章