Microsoft promises more bug payouts, with or without a bounty program

The Register
2025.12.12 13:40
portai
I'm PortAI, I can summarize articles.

Microsoft is revamping its bug bounty program to reward researchers for finding vulnerabilities across all products, even without established bounty schemes. The "in scope by default" approach will incentivize research on high-risk areas, offering monetary awards for critical vulnerabilities impacting Microsoft's services. This shift aims to enhance security amid evolving threats, covering new products and services, including cloud and AI. Microsoft paid over $17 million in awards last year and plans to increase spending.