Cyber Security News

Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year

Microsoft has awarded more than $20 million to 562 security researchers through its bug bounty program, marking the largest annual payout in the company’s history.

Researchers from 64 countries reported security flaws that could have affected Microsoft customers, cloud users, businesses, and consumers worldwide.

The Microsoft Security Response Center, also known as MSRC, said the results show the value of coordinated vulnerability disclosure. Under this process, security researchers privately report weaknesses to Microsoft before attackers can exploit them.

Microsoft then investigates the issue, creates a fix, and releases security updates to protect customers. The new record is a major increase from the previous year. Microsoft paid $17 million to 344 researchers from 59 countries last year.

The latest figures show that the company is receiving more reports, rewarding more researchers, and expanding the reach of its vulnerability research programs.

Microsoft Awards $20M in Record Bounty Year

Bug bounty programs are an important part of modern cybersecurity. Independent researchers test products, services, and platforms for weaknesses that internal security teams may not find.

Their work helps companies identify risks before they become public incidents, data breaches, ransomware attacks, or zero-day exploits.

Microsoft said every valid vulnerability report allows its engineers to reduce risk before criminals can use the flaw against customers.

The company highlighted the research community’s role in securing cloud services, artificial intelligence systems, enterprise software, and consumer technologies. The growth was especially noticeable during the second half of the year, when Microsoft received a higher volume of submissions.

The company said increased researcher participation and wider use of AI tools in security research contributed to this rise. AI can help researchers review code, analyze attack paths, identify unusual behavior, and test complex systems more efficiently.

Microsoft’s Zero Day Quest event also played a key role in the record year. The live hacking event brought researchers from 20 countries to Microsoft’s Redmond campus.

Participants worked directly with Microsoft security and engineering teams to examine high-priority scenarios involving cloud and AI technologies.

During Zero Day Quest, researchers submitted nearly 700 vulnerability reports and received $2.3 million in awards. The event allowed Microsoft to collect reports rapidly while helping researchers better understand the company’s products, security priorities, and vulnerability reporting process.

Microsoft has also expanded the scope of its bounty rewards program. Eligible findings can now include certain open-source software, third-party components, and Microsoft cloud services that may not have qualified under older bounty rules.

Since this expansion, Microsoft has received more than 300 additional reports and paid over $800,000 for vulnerabilities that previously may have gone unrewarded.

According to the MSRC report, the record payout highlights the growing reliance on external security researchers as modern software environments span cloud platforms, identity systems, AI services, open-source software, and third-party dependencies.

Microsoft said finding weaknesses across its broad attack surface requires collaboration with the global security community, thanking researchers whose reports, technical expertise, and coordinated disclosures help strengthen security for billions of users worldwide.

Researchers interested in participating can learn more about Microsoft’s vulnerability rewards programs through the company’s official bug bounty portal at aka.ms/bugbounty.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago