$20M+ in Microsoft bug bounties paid out in last 12 months

Gaishan1 pts0 comments

AI helps Microsoft bug hunters chase a record $20M payday

Jump to main content

Search

REG AD

Security

AI helps Microsoft bug hunters chase a record $20M payday

Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports

Connor Jones

Connor<br>Jones

Cybersecurity reporter

Published<br>tue 4 Aug 2026 // 15:40 UTC

Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers.<br>The total was a Redmond record, as was the number of those submitting bug reports – despite having to navigate a sometimes frustrating submissions process.<br>For comparison, the previous year's program, which itself set a new company record, paid 344 researchers around $17 million.

REG AD

You could argue that the numbers do not represent a fair fight, however. Microsoft expanded its bug bounty program in December 2025, changing reports to what it calls "In Scope By Default."

REG AD

Under the policy, critical vulnerabilities became eligible for rewards if they had a direct and demonstrable impact on Microsoft's online services, even when the faulty code belonged to a third party or an open source project.<br>In short, Microsoft had opened the door to paying out a shedload more each year.<br>Microsoft introduced the policy roughly halfway through the bounty year and said it accounted for $800,000 in rewards that would not previously have been available.<br>Another $2.3 million was awarded through Zero Day Quest, Microsoft's security research challenge and live hacking event.<br>The increased number of reports this year can also be partially explained by the noticeable influx of submissions during the second half of the year, Microsoft said, which the company attributed in part to "the growing use of AI to support security research."<br>Microsoft has also attributed its increasingly crowded Patch Tuesdays partly to its own use of advanced AI models for vulnerability discovery.<br>July's 622 vulnerabilities pummeled the previous record of 206, set only a month earlier. June had itself surpassed April's 165, which at the time was Microsoft's second-biggest Patch Tuesday ever, and May's 137.<br>Days before the record-breaking July Patch Tuesday, Microsoft's Windows + Devices veep warned customers to expect more of the same now that AI plays a big part in vulnerability discovery, both inside Microsoft and by external bounty hunters.

REG AD

However, Microsoft Executive VP of Windows + Devices Pavan Davuluri was quick to point out that the company offers customers a suite of automated patching tools to ease the burden, but didn't mention anything about tools to fix the machines its Windows updates so often borks, like Intel-based Dells.

MORE CONTEXT

Microsoft's first Windows 10 ESU Patch Tuesday release fails for some

Microsoft slows Windows 11 24H2 Patch Tuesday due to a 'compatibility issue'

Microsoft broke DHCP for Windows Server last Patch Tuesday

Microsoft yanks Windows 11 preview update after install failures

As well as navigating the rapid AI-ification of vulnerability research, and the onslaught of reports that came with it, Microsoft has arguably faced a bigger bug problem this year amid unverified speculation that one prolific researcher may be a former Microsoft staffer.<br>Using the name NightmareEclipse, a researcher with deep knowledge of Microsoft's software and an equally apparent disdain for the company spent Q2 dropping sophisticated zero-days at will.<br>NightmareEclipse claims that attempts to report vulnerabilities to Microsoft ended with them being insulted, humiliated, and left homeless. They subsequently began publishing zero-days outside coordinated disclosure, often shortly after Patch Tuesday, saying they wanted to cause Microsoft maximum pain.<br>These ranged from serious privilege escalation flaws leading to SYSTEM access to BitLocker bypasses, and the approach seemed to have inspired at least two other aggrieved researchers to just drop the exploit code outside of responsible disclosure.<br>Microsoft responded by threatening to involve its Digital Crimes Unit in the dispute with NightmareEclipse, suggesting it was willing to engage law enforcement, although this went down about as well as you would expect. ®

security<br>microsoft<br>ai and ml

REG AD

AI + ML

AMD's results spotlight risks of putting all your AI eggs in too few baskets

The House of Zen's new Helios racks, Venice Epycs, may dent Nvidia's dominance — if the bubble doesn't pop first

EDGE AND IOT

Dev proves LLMs will run on anything – even a $10 microcontroller

Nearly 10 tok/s and it's mostly coherent — What's not to like?

From individual achievement to partner impact

PARTNER CONTENT: Databricks survey data suggests certified professionals lift partner delivery capacity, customer credibility, and AI readiness well beyond the individuals who earn the credential

ai and ml

OpenAI wants teachers and profs to foist their work off on ChatGPT

New plugins...

microsoft patch windows record year tuesday

Related Articles