logo

Microsoft promises more bug payouts, with or without a bounty program

ID: ad078aee-7ed4-55d3-95be-b48c14d620a1

STIX ID: report--ad078aee-7ed4-55d3-95be-b48c14d620a1

Feed Name: The Register (Security)

Date Published: 2025-12-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Microsoft announced at Black Hat Europe an overhaul of its bug bounty program to an in scope by default model, offering rewards for critical vulnerabilities across all Microsoft-managed products and services, including third-party and open-source components, with standardized payouts by severity and class. The approach extends coverage to new products at launch, targets high-risk areas across cloud and AI, and anticipates increased spending beyond the $17M awarded last year, while acknowledging ongoing community concerns about response times and triage raised to the Microsoft Security Response Center and reported by outlets like *The Register*.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.