logo

Microsoft bounty program now includes any flaw impacting its services

ID: 707ca63e-73e0-507b-8c20-542f010b4eca

STIX ID: report--707ca63e-73e0-507b-8c20-542f010b4eca

Feed Name: Bleeping Computer

Date Published: 2025-12-11

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft expanded its bug bounty program to cover critical vulnerabilities impacting any Microsoft online service—including third-party and open-source components—aligning with its Secure Future Initiative. The company reported over $33M in bounty payouts across the last two years and detailed additional security measures such as disabling ActiveX in Microsoft 365/Office 2024, strengthening Microsoft 365 security defaults, adding Teams screen-capture protections, and enhancing Entra ID sign-in defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.