AI helps Microsoft bug hunters chase a record $20M payday
Jump to main content
Search
REG AD
Security
AI helps Microsoft bug hunters chase a record $20M payday
Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
Connor Jones
Connor<br>Jones
Cybersecurity reporter
Published<br>tue 4 Aug 2026 // 15:40 UTC
Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers.<br>The total was a Redmond record, as was the number of those submitting bug reports – despite having to navigate a sometimes frustrating submissions process.<br>For comparison, the previous year's program, which itself set a new company record, paid 344 researchers around $17 million.
REG AD
You could argue that the numbers do not represent a fair fight, however. Microsoft expanded its bug bounty program in December 2025, changing reports to what it calls "In Scope By Default."
REG AD
Under the policy, critical vulnerabilities became eligible for rewards if they had a direct and demonstrable impact on Microsoft's online services, even when the faulty code belonged to a third party or an open source project.<br>In short, Microsoft had opened the door to paying out a shedload more each year.<br>Microsoft introduced the policy roughly halfway through the bounty year and said it accounted for $800,000 in rewards that would not previously have been available.<br>Another $2.3 million was awarded through Zero Day Quest, Microsoft's security research challenge and live hacking event.<br>The increased number of reports this year can also be partially explained by the noticeable influx of submissions during the second half of the year, Microsoft said, which the company attributed in part to "the growing use of AI to support security research."<br>Microsoft has also attributed its increasingly crowded Patch Tuesdays partly to its own use of advanced AI models for vulnerability discovery.<br>July's 622 vulnerabilities pummeled the previous record of 206, set only a month earlier. June had itself surpassed April's 165, which at the time was Microsoft's second-biggest Patch Tuesday ever, and May's 137.<br>Days before the record-breaking July Patch Tuesday, Microsoft's Windows + Devices veep warned customers to expect more of the same now that AI plays a big part in vulnerability discovery, both inside Microsoft and by external bounty hunters.
REG AD
However, Microsoft Executive VP of Windows + Devices Pavan Davuluri was quick to point out that the company offers customers a suite of automated patching tools to ease the burden, but didn't mention anything about tools to fix the machines its Windows updates so often borks, like Intel-based Dells.
MORE CONTEXT
Microsoft's first Windows 10 ESU Patch Tuesday release fails for some
Microsoft slows Windows 11 24H2 Patch Tuesday due to a 'compatibility issue'
Microsoft broke DHCP for Windows Server last Patch Tuesday
Microsoft yanks Windows 11 preview update after install failures
As well as navigating the rapid AI-ification of vulnerability research, and the onslaught of reports that came with it, Microsoft has arguably faced a bigger bug problem this year amid unverified speculation that one prolific researcher may be a former Microsoft staffer.<br>Using the name NightmareEclipse, a researcher with deep knowledge of Microsoft's software and an equally apparent disdain for the company spent Q2 dropping sophisticated zero-days at will.<br>NightmareEclipse claims that attempts to report vulnerabilities to Microsoft ended with them being insulted, humiliated, and left homeless. They subsequently began publishing zero-days outside coordinated disclosure, often shortly after Patch Tuesday, saying they wanted to cause Microsoft maximum pain.<br>These ranged from serious privilege escalation flaws leading to SYSTEM access to BitLocker bypasses, and the approach seemed to have inspired at least two other aggrieved researchers to just drop the exploit code outside of responsible disclosure.<br>Microsoft responded by threatening to involve its Digital Crimes Unit in the dispute with NightmareEclipse, suggesting it was willing to engage law enforcement, although this went down about as well as you would expect. ®
security<br>microsoft<br>ai and ml
REG AD
AI + ML
AMD's results spotlight risks of putting all your AI eggs in too few baskets
The House of Zen's new Helios racks, Venice Epycs, may dent Nvidia's dominance — if the bubble doesn't pop first
EDGE AND IOT
Dev proves LLMs will run on anything – even a $10 microcontroller
Nearly 10 tok/s and it's mostly coherent — What's not to like?
From individual achievement to partner impact
PARTNER CONTENT: Databricks survey data suggests certified professionals lift partner delivery capacity, customer credibility, and AI readiness well beyond the individuals who earn the credential
ai and ml
OpenAI wants teachers and profs to foist their work off on ChatGPT
New plugins...