Microsoft pays security researchers $20M following AI-backed surge in bug reports
Microsoft’s Bounty Program paid out a record $20 million to 562 security researchers across 64 countries for identifying vulnerabilities in Microsoft products and services. This marks a significant increase from the previous year’s $17 million distributed to 344 researchers, reflecting growing participation in the program.
The surge in bug reports has been partly driven by the rise of AI tools, which are enabling researchers to identify flaws more efficiently. The amount researchers receive varies depending on the type of vulnerability reported, with cloud programs and Zero Day Quest vulnerabilities commanding premium payouts. The program, which has operated for several years, continues to be a critical component of Microsoft’s security infrastructure, leveraging the global security research community to identify and address potential threats before they can be exploited.