Security News

Cybersecurity news aggregator

🪟
INFO News SecurityWeek

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

  • What: Microsoft paid $20 million through its bug bounty program
  • Impact: Over 500 researchers were rewarded for reporting vulnerabilities
Read Full Article →

Vulnerabilities Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. By Eduard Kovacs | August 4, 2026 (1:18 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Microsoft announced on Monday that over the past year it has paid out more than $20 million through its bug bounty programs. Between July 1, 2025, and June 30, 2026, the company received vulnerability reports through its 15 bug bounty programs from researchers across 64 countries. Microsoft said it received 2,531 eligible reports, and 562 researchers have been awarded a total of over $20 million, with the largest single payout reaching $200,000. [ Read: Will AI Kill the Bug Bounty Industry? ] The total amount includes $2.3 million given to participants at the Zero Day Quest hacking contest. In addition, $800,000 was paid out through new initiatives, such as those targeting vulnerabilities in third-party and open source code . Microsoft noted that it saw a significant increase in submission volume during the second half of the year, which it attributed to “both strong engagement from the research community and the growing use of AI to support security research”. Advertisement. Scroll to continue reading. Microsoft paid out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023. While the latest numbers show that Microsoft’s bug bounty programs are increasingly successful, not all researchers are happy with the company’s handling of vulnerability reports. A researcher who uses the online moniker Chaotic Eclipse and Nightmare Eclipse has released the details of several zero-days without giving Microsoft the chance to patch them. Some of the flaws ended up being exploited in the wild . Chaotic Eclipse has voiced strong dissatisfaction with Microsoft, alleging that the company mishandled vulnerability reports, ignored communications, withheld bounty payments, deleted the researcher’s reporting account, and breached a prior agreement. Related : Google Paid Out $17 Million in Bug Bounty Rewards in 2025 Related : Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date Related : Meta Paid Out $4 Million via Bug Bounty Program in 2025 Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations Semiconductor Firm Analog Devices Discloses Data Breach 1 in 5 Data Center Assets Are Within Easy Reach of Attackers Cisco Secure FMC Zero-Day Exploited in the Wild ThreatLocker Raises $190 Million in Series F Funding Critical VM Escape Vulnerability Patched in VMware ESXi OpenAI’s Rogue AI Ventured Beyond Hugging Face Latest News New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations River Bank Says Hackers Deleted Data Stolen in Ransomware Attack Horizon3 Raises $250 Million to Fund Continuing Growth N‑able Patches Vulnerability Exploited to Hack N-central Servers Brinks Home Discloses Data Breach as Hackers Leak Files Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move PNC Financial Services Group has appointed Christian Winward as CISO. Brian Gumbel has joined Armadin as Chief Revenue Officer. EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO. More People On The Move Expert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email

Share this article