AI helps Microsoft bug hunters chase a record $20M payday
Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
Microsoft has announced a record-breaking $20 million payout to security researchers through its bug bounty program between July 2025 and June 2026. The company acknowledged the increased number of submissions and payouts, citing the broader scope of its bug bounty initiative called "In Scope By Default." This change in policy, implemented halfway through the year, enabled the company to reward critical vulnerabilities, even if they originated in third-party or open-source projects.
In addition to the expanded policy, Microsoft's Zero Day Quest security research challenge contributed to the substantial payouts. The surge in submissions and payouts can also be attributed to the growing use of AI to support security research, a factor Microsoft highlighted as a contributing element to the record-breaking achievements.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
Also reported by 1 other outlet
- AI helps Microsoft bug hunters chase a record $20M payday theregister.com