$20 Million Bug Bounty Payout Sets New Record for Microsoft
Microsoft has paid out a record-breaking $20 million to security researchers through its Bounty Program. The program, which has been in place for years, rewards researchers for identifying and reporting vulnerabilities across Microsoft's products and services.
The payouts were awarded to 562 researchers from 64 countries, with many receiving smaller awards for reporting vulnerabilities that did not meet the maximum payout thresholds. Cloud programs and Zero Day Quest vulnerabilities are capped at $100,000 per vulnerability, while reporting an Endpoint and On-Premises program vulnerability can be worth up to $250,000.
Microsoft expanded the scope of its researcher awards last year to include open-source software, third-party components, and Microsoft cloud services. The company credited the increase in submissions in part to the use of AI by security researchers, as well as AI's ability to help find and fix vulnerabilities. However, this has also led to an 'AI arms race' between malicious actors and security researchers.
Microsoft also highlighted the success of its Zero Day Quest event, which saw researchers from 20 countries travel to Microsoft's campus in Redmond, Washington, where over 700 vulnerability reports were filed and over $2.3 million was awarded.