Microsoft today said it acquired IoT security ReFirm Labs for an undisclosed amount.

ReFirm built its firmware analysis technology on Binwalk open source software, the international standard for extracting firmware images used by more than 50,000 global organizations. It analyzes thousands of device types for firmware security issues including unpatched common vulnerabilities and exposures (CVEs) and insecure secrets, and Microsoft says this technology will boost its existing IoT and operational technology (OT) security capabilities via Azure Defender for IoT.

“Together, we will provide device builders and customers the ability to both discover, protect, and assess device risk both at the firmware and network level and then patch devices with an easy-to-use cloud-based solution,” wrote David Weston, Microsoft’s director of enterprise and OS security, in a blog post.

This is Microsoft’s second IoT security acquisition in less than a year. In June 2020, it bought CyberX for a reported $170 million. CyberX’s agentless software continuously monitors and provides visibility into unmanaged IoT and industrial control system devices across IT and OT environments.

Microsoft has pledged to invest $5 billion in IoT by 2022.

In his blog post, Weston says that Microsoft has seen a rapid increase in firmware attacks where credentials, encryption keys, and other sensitive information are stored in memory.

In a March survey of 1,000 security decision-makers, Microsoft found that 83% had experienced some level of firmware security incident. However, only 29% are allocating resources to protect firmware.

Additionally, Microsoft’s Azure Defender for IoT team (formerly CyberX), working with the U.S. Department of Homeland Security (DHS), recently discovered a series of more than 25 critical severity vulnerabilities in IoT and OT devices.