Microsoft forks out record-breaking sums with expanded bug bounty program
Hundreds of security researchers won a share of $20 million after the tech giant expanded its bug hunting scheme
Microsoft has dished out its biggest collection of bug bounties ever over the last year, awarding more than $20 million to 562 security researchers.
Microsoft Security Response Center (MSRC) said the figure was well up on the $17 million distributed the year before to 344 researchers from 59 countries – itself a Microsoft Bounty Program record.
Part of the reason for the increase is the company's new 'In Scope By Default' policy.
Last year, it expanded its vulnerability awards portfolio to recognize 'impactful' research that fell outside the scope of traditional bounty programs, including eligible open source software, third-party components, and Microsoft cloud services.
Since then, the tech giant said it's received more than 300 additional reports and awarded more than $800,000 for vulnerabilities that wouldn't previously have qualified for bounty awards.
The firm noted it also saw a notable increase in submission volume during the second half of the year.
"Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers," said the MSRC team.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies."
Microsoft Zero Day Quest
The figures include findings from this year's Microsoft Zero Day Quest, which saw security researchers from 20 countries meeting at Microsoft’s Redmond campus to collaborate directly with security and engineering teams.
This research challenge and live hacking event was focused on high-priority security scenarios across Microsoft’s cloud and AI platforms. That saw nearly 700 vulnerability reports submitted, with researchers collecting $2.3 million in awards.
Individual awards depend on the type of vulnerability reported, with cloud programs and Zero Day Quest vulnerabilities capped at $100,000 per vulnerability. Endpoint and on-premises program vulnerabilities, meanwhile, can earn bug-hunters up to $250,000.
"This year’s record-breaking results, including more than $20 million in awards and recognition for 562 researchers, reflect the impact of a strong partnership between Microsoft and the global security research community," said the team.
"Whether participating through a traditional bounty submission, collaborating through coordinated vulnerability disclosure, or joining initiatives such as Zero Day Quest, researchers continue to play a vital role in protecting customers around the world."
Bug bounty programs are booming
Bug bounty programs have long been a means for enterprises to weed out vulnerabilities that have flown under the radar, either during development or in the wake of updates.
With AI now in the mix, researchers are accelerating vulnerability hunting, identifying more flaws than ever. Some programs are struggling to keep up with the volume of reports, however.
Moreover, AI-generated reports are proving troublesome for organizations, particularly in the open source community.
As ITPro reported last year, security report triage worker Seth Larson revealed he’d observed a marked uptick in “extremely low-quality, spammy, and LLM-hallucinated security reports”.
Earlier this year, Daniel Stenberg, lead maintainer of command line interface (CLI) tool Curl, went so far as to shut down the firm's bug bounty scheme after receiving dozens of reports that didn't actually show a concrete vulnerability.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
This one engineering role could be the key to building a truly data-driven enterpriseNews AI has increased the expectation for fast, or even instant, decisions. Data streaming engineers could help leaders keep pace
-
AMD CEO Lisa Su hails ‘excellent quarter’ as data center revenue surges 107%News The record-breaking quarter comes as AMD prepares to roll out its Helios rack-scale architecture later this year
-
'It delivers world-class performance at 50 percent of the cost of leading models': Microsoft unveils cut-price AI for security with latest in-house model launchNews Pairing the MAI security model with GPT-5.4 gives benchmark leading results at half the cost, according to the tech giant
-
Why Microsoft paused Patch Tuesday updates for some Dell devicesNews Select devices running Intel Innovation Platform Framework drivers encountered “poor performance”
-
Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effectNews The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft
-
Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victimsNews Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware
-
Beware of emails threatening a code of conduct reviewNews A widespread phishing campaign has targeted tens of thousands of employees
-
OpenAI is cracking down on AI misuse with a new bug bounty programNews Submissions don't have to be security vulnerabilities, OpenAI says, just the potential to cause material harm
-
Is your new hire an AI clone? Microsoft says North Korean hackers are using AI to impersonate job seekers and steal company secretsNews The groups are increasingly using face-changing or voice-changing software to make their fake identities more plausible
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers