Microsoft Breaks Record with $20 Million Bounty Payment to Security Researchers
Microsoft has paid out a record-breaking $20 million to security researchers as part of its bounty program, which aims to protect customers through coordinated vulnerability disclosure. The company's July Patch Tuesday security rollout fixed a record 570 vulnerabilities across its ecosystem, with only two actively being exploited by attackers beforehand.
The Microsoft Bounty Program has seen significant growth over the past year, with 562 researchers from 64 different countries participating and submitting reports that earned them rewards. This effort is crucial in preventing zero-day exploits, which can become vulnerabilities if not mitigated before threat actors get a chance to exploit them.
A spokesperson for Microsoft's Security Response Center confirmed that the company had seen a notable increase in vulnerability reports submitted, particularly during 2026, partly due to the growing use of AI to support security research. However, it is essential to note that skilled security researchers are necessary to ensure that red herrings are not forwarded as confirmed vulnerabilities and to put findings to the test.