AI helps Microsoft bug hunters chase a record $20M payday
Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
In 2025, Microsoft announced that its bug bounty program had paid out more than $20 million to 562 researchers, marking a new record for the company. This figure surpassed the previous year's payout of $17 million, which in turn had set a record for Microsoft itself. The increase in payouts can be attributed to the implementation of a new policy in December 2025, which expanded the scope of eligible vulnerabilities to include those that affected Microsoft's online services, even if the faulty code belonged to third parties or open-source projects.
This change, dubbed "In Scope By Default," led to an additional $800,000 in rewards that would not have been available under the previous rules. Microsoft also attributed part of the boost in submissions to the growing use of AI in security research, which resulted in more researchers participating in the program. The company's own use of advanced AI models for vulnerability discovery may have also contributed to the surge in Patch Tuesdays, with July 2025 witnessing 622 vulnerabilities, surpassing the previous record of 206 set just a month earlier.
Microsoft's Windows + Devices VP warned customers to anticipate more such vulnerabilities as AI plays a significant role in vulnerability discovery. Despite the increased activity, Microsoft offered customers automated patching tools to ease the burden. However, the company's response to a prolific researcher named NightmareEclipse, who allegedly published zero-days outside of coordinated disclosure, raised concerns over the handling of such situations.
Written by urgent.news from The Register's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- AI helps Microsoft bug hunters chase a record $20M payday theregister.com