news.mlab.sh
Back to the feed
threat-intel

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Medium
Summary

Microsoft significantly increased its bug bounty payouts, reaching over $20 million in the past year and rewarding 562 researchers across 64 countries. The company’s programs saw a substantial rise in submissions, partly due to the use of AI in security research, but a researcher expressed serious concerns about Microsoft's handling of vulnerability reports and delayed payments.

Microsoft announced that it had paid out over $20 million through its bug bounty programs between July 1, 2025, and June 30, 2026. The company received 2,531 eligible vulnerability reports from researchers located in 64 countries. A total of 562 researchers were awarded payments, with the highest single payout reaching $200,000. This amount includes $2.3 million awarded to participants at the Zero Day Quest hacking contest, and an additional $800,000 through new initiatives focused on vulnerabilities in third-party and open-source code. Microsoft reported a notable increase in submission volume during the second half of 2025, attributing this growth to both increased engagement from the security research community and the growing adoption of AI tools to assist in security research. However, a researcher known as Chaotic Eclipse and Nightmare Eclipse expressed significant dissatisfaction with Microsoft’s handling of vulnerability reports, alleging that the company ignored communications, withheld payments, deleted the researcher’s reporting account, and violated a prior agreement. The researcher disclosed several zero-day vulnerabilities without allowing Microsoft to implement patches, and some of these flaws were subsequently exploited in the wild.

Read the full article at SecurityWeek