Microsoft rewards $100,000 to hacker for Internet Explorer bug, issues update

Advertisement
By Reuters | Updated: 9 October 2013 10:03 IST
Microsoft Corp said on Tuesday it is paying a well-known hacking expert more than $100,000 for finding security holes in its software, one of the largest such bounties awarded to date by a high-tech company.

The software maker also released a much anticipated update to Internet Explorer, which it said fixes a bug that made users of the world's most popular browser vulnerable to remote attack.

James Forshaw, who heads vulnerability research at London-based security consulting firm Context Information Security, won Microsoft's first $100,000 bounty for identifying a new "exploitation technique" in Windows, which will allow it to develop defenses against an entire class of attacks, the software maker said on Tuesday.

Advertisement

Forshaw earned another $9,400 for identifying security bugs in a preview release of Microsoft's Internet Explorer 11 browser, Katie Moussouris, senior security strategist with Microsoft Security Response Center, said in a blog.

Microsoft unveiled the reward programs four months ago to bolster efforts to prevent sophisticated attackers from subverting new security technologies in its software, which runs on the vast majority of the world's personal computers.

Advertisement

Forshaw has been credited with identifying several dozen software security bugs. He was awarded a large bounty from Hewlett-Packard Co for identifying a way to "pwn," or take ownership of, Oracle Corp's Java software in a high-profile contest known as Pwn2Own (pronounced "pown to own").

Microsoft also released an automatic update to Internet Explorer on Tuesday afternoon to fix a security bug that it first disclosed last month.

Advertisement

Researchers say hackers initially exploited that flaw to launch attacks on companies in Asia in an operation that the cybersecurity firm FireEye has dubbed DeputyDog.

Marc Maiffret, chief technology officer of the cybersecurity firm BeyondTrust, said the vulnerability was later more broadly used after Microsoft's disclosure of the issue brought it to the attention of cyber criminals.

Advertisement

He is advising computer users to immediately install the update to Internet Explorer, if they do not have their PCs already set to automatically download updates.

"Any time they patch something that has already been used (to launch attacks) in the wild, then it is critical to apply the patch," Maiffret said.

That vulnerability in Internet Explorer was known as a "zero-day" because Microsoft, the targeted software maker, had zero days notice to fix the hole when the initial attacks exploiting the bug were discovered.

In an active, underground market for "zero day" vulnerabilities, criminal groups and governments sometimes pay $1 million or more to hackers who identify such bugs.

© Thomson Reuters 2013

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Internet, Internet Explorer, Microsoft
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  2. Anthropic's Source Code Leak Reveals Critical Details About Claude Code
  3. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  4. Honor X80i With MediaTek Dimensity 6500 Elite Chip Launched: See Price
  5. These Three Pro Models Could Launch as Part of the Motorola Edge 70 Series
  6. Google AI Pro Subscribers Now Get 5TB of Storage Across Drive, Photos
  7. Honor Play 80 Pro With a 7,000mAh Battery Arrives at This Price
  8. Oppo Find X9 Ultra Runs Geekbench With These Key Specifications
  9. Redmi Note 15 SE 5G Debuts in India With a Vegan Leather Finish: See Price
  10. Meta Reportedly Warns WhatsApp Users About This Fake App Spying on Them
  1. Naughty Dog's Neil Druckmann Mentions 'Road Ahead' for the Last of Us, Teasing the Last of Us Part 3
  2. Repu Udayam 10 Gantalaku Brings a Race Against Time to Prime Video
  3. Honor X80i Launched With 7,000mAh Battery, MediaTek Dimensity 6500 Elite Chip: Price, Specifications
  4. Honor Play 80 Pro Launched With 7,000mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
  5. Hong Kong Misses March Target for Stablecoin Licences, HKMA Yet to Approve Issuers
  6. Samsung Galaxy Buds 'Able' Reportedly Spotted in Development, Model Number Raises Questions
  7. Khakee Circus OTT Release Date: When and Where to Watch it Online?
  8. Meta Reportedly Warns WhatsApp Users About Fake App Spying on Android, iPhone Users
  9. Anthropic’s Claude Code Update Leaks Source Code, Reveals Always-on Agent and Memory Optimisation: Report
  10. Sony Xperia 1 VIII Leaked Renders Hint at Major Design Update Including Redesigned Rear Camera Module
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.