Tech News : Microsoft Pays Bug-Finders $20 Million

August 10, 2026

Tech News : Microsoft Pays Bug-Finders $20 Million

Microsoft has paid more than US$20 million to ethical hackers over the past year, its largest bug bounty payout ever, reflecting how the company is increasingly relying on independent security researchers to help identify vulnerabilities before cyber criminals can exploit them.

Bug Bounty Programme Payouts Up

The company's Microsoft Security Response Center (MSRC) has revealed that its bug bounty programme awarded more than US$20 million to 562 security researchers from 64 countries during the past year, making it the largest payout and the broadest researcher participation in the programme's history.

The figures represent a substantial increase on the previous year, when Microsoft distributed US$17 million to 344 researchers from 59 countries.

Microsoft says the growth reflects both stronger engagement from the global security research community and important changes it has made to its vulnerability rewards programme.

As the MSRC team explained in an online announcement: " Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers."

The company added:  "The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies."

Why Are The Rewards Increasing?

One of the biggest reasons is Microsoft's new "In Scope by Default" policy. For example, previously, researchers were generally rewarded only for vulnerabilities affecting products or services that had been specifically included within Microsoft's bug bounty programme.

Under the revised approach, announced last year, Microsoft now rewards researchers for finding critical vulnerabilities affecting its online services even when those weaknesses originate in eligible third-party software, open-source projects or external components used by Microsoft.

The policy reflects the reality that modern cloud services increasingly depend on software developed by many different organisations rather than a single vendor.

As Tom Gallagher, Vice President of Engineering at the Microsoft Security Response Center, explained:  "If a critical vulnerability has a direct and demonstrable impact on our online services, it's eligible for a bounty award. Regardless of whether the code is owned and managed by Microsoft, a third-party, or is open source, we will do whatever it takes to remediate the issue."

Since introducing the expanded programme, Microsoft says it has received more than 300 additional vulnerability reports and paid more than US$800,000 for discoveries that would previously have fallen outside the scope of its rewards programme.

Working With The Research Community

Microsoft has also expanded its Zero Day Quest initiative, bringing together security researchers from 20 countries at its Redmond headquarters to collaborate directly with Microsoft's engineering and security teams.

The live hacking event focused on Microsoft's cloud and AI platforms, generating nearly 700 vulnerability reports and awarding researchers a combined US$2.3 million.

Rather than viewing external researchers as outsiders, Microsoft increasingly treats them as an extension of its own security operation.

As the MSRC team said:  "This year's record-breaking results, including more than US$20 million in awards and recognition for 562 researchers, reflect the impact of a strong partnership between Microsoft and the global security research community."

It added:  "Researchers continue to play a vital role in protecting customers around the world."

Individual rewards can also be substantial. Depending on the vulnerability involved, Microsoft's programmes now pay up to US$100,000 for many cloud vulnerabilities and as much as US$250,000 for qualifying endpoint and on-premises security issues.

Why AI Is Changing Bug Hunting

The announcement also reflects a wider change taking place across cyber security. Artificial intelligence is helping many security researchers analyse software more quickly, automate repetitive testing and identify potential weaknesses that previously required much more manual investigation.

Microsoft says it experienced a notable increase in vulnerability submissions during the second half of the year, reflecting both growing participation from researchers and the increasing use of AI to support security research.

At the same time, AI is creating new challenges. For example, security teams across the industry have reported growing numbers of low-quality vulnerability reports generated largely by AI tools, requiring significant effort to assess before determining whether a genuine security issue exists.

Microsoft's expanded programme therefore reflects not only greater investment in security research but also the increasing need to distinguish valuable discoveries from automated noise.

Security Through Collaboration

Perhaps the most significant aspect of Microsoft's announcement is what it says about how cyber security itself is changing.

Rather than relying solely on internal testing, organisations are increasingly recognising that thousands of independent researchers examining software from different perspectives can identify vulnerabilities that internal teams may never encounter.

Microsoft's decision to reward research involving third-party code also acknowledges that modern technology ecosystems are highly interconnected. A vulnerability affecting an open-source component may ultimately present just as much risk to Microsoft customers as one discovered within Microsoft's own software.

The company's approach therefore broadens responsibility for security while encouraging researchers to investigate the areas most likely to matter to customers.

What Does This Mean For Your Business?

For businesses, Microsoft's record investment should provide reassurance that the company is continuing to strengthen the security of the products and cloud services on which many organisations depend every day. Finding vulnerabilities before attackers do remains one of the most effective ways of reducing cyber risk, and Microsoft's willingness to reward responsible disclosure demonstrates how seriously it now views collaborative security research.

The announcement also highlights an important change in how software security is managed. Modern applications increasingly rely on open-source software, cloud infrastructure and third-party components, meaning vulnerabilities can emerge well beyond the boundaries of a single vendor's own code. Businesses should therefore expect software suppliers to take greater responsibility for securing their wider technology ecosystems rather than focusing solely on their own products.

Microsoft's latest figures, therefore, seem to show that cyber security is becoming an increasingly collaborative discipline. As AI accelerates both software development and vulnerability discovery, partnerships between technology companies and independent researchers are likely to become even more important in identifying weaknesses before malicious attackers have the opportunity to exploit them.

Featured Article : AI Creates Brand New (Biological) Viruses
August 10, 2026
Featured Article : AI Creates Brand New (Biological) Viruses
Tech Insight : AI Agents Getting More Deceptive & Tricky
August 10, 2026
Tech Insight : AI Agents Getting More Deceptive & Tricky
More Posts