Microsoft bounty program now includes any flaw impacting its services
ID: 707ca63e-73e0-507b-8c20-542f010b4eca
STIX ID: report--707ca63e-73e0-507b-8c20-542f010b4eca
Feed Name: Bleeping Computer
Microsoft expanded its bug bounty program to cover critical vulnerabilities impacting any Microsoft online service—including third-party and open-source components—aligning with its Secure Future Initiative. The company reported over $33M in bounty payouts across the last two years and detailed additional security measures such as disabling ActiveX in Microsoft 365/Office 2024, strengthening Microsoft 365 security defaults, adding Teams screen-capture protections, and enhancing Entra ID sign-in defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
