A record-breaking year for Microsoft's Bounty Programs!
This year, Microsoft awarded more than $20 million to 562 security researchers, the highest total payout and largest number of researchers recognized in program history.
Read the full blog to learn more about the impact of the global security research community: https://t.co/nrkGap6nDi
@devyn@msftsecresponse Echoing @msftsecresponse, wonderful research on .NET, Devyn! Thank you for your continued patience as we reviewed your case (under first Standard Award Policy and then the .NET Bounty Program. Your follows-up were invaluable and I'm glad we were able to award your research.
As announced by Tom Gallagher (@secbughunter), VP of Engineering, MSRC, on stage at Black Hat Europe, we’re evolving our bug bounty program. Now, high-severity vulnerabilities that directly impact Microsoft online services are eligible for bounty awards, whether the code is Microsoft-owned, third-party, or open source.
This expanded scope applies retroactively to cases from the past 90 days, ensuring recent impactful research is recognized and rewarded. These payments have already begun.
Learn more about the changes, our commitment to the security community, and how you can participate: https://t.co/xkBJ285tAM
#BHEU
At just 13 years old, Dylan Ryan-Zilavy became the youngest security researcher to collaborate with MSRC. What started with Scratch and HTML quickly evolved into submitting impactful vulnerability reports, respectfully challenging scope decisions, and even helping shape MSRC’s bug bounty policies. Today, Dylan is not only one of our youngest collaborators, but also one of our most thoughtful, balancing high school with cello, science competitions, and security research. In April, he placed 3rd at Microsoft’s Zero Day Quest, competing alongside seasoned professionals.
Read more about Dylan’s path, challenges, and achievements on the MSRC blog: https://t.co/X06hCV0phm
#bugbounty
We’re excited to highlight Brad Schlintz's (@nmdhkr) incredible journey in security research! From transitioning out of a traditional 9‑to‑5 to becoming a world‑class vulnerability researcher, Brad has carved out a life defined by curiosity, freedom, and impact. His dedication to mastering the craft of vulnerability research has not only earned him the #5 spot on the 2025 MVR leaderboard but also led him to qualify for Zero Day Quest in both 2025 and 2026.
Check out his full story and the path that led him to become one of MSRC’s top contributors: https://t.co/A5R8hN2vR6
When MSRC and top Microsoft 365 security researchers meet over coffee, the conversation naturally turns to how we can make the Bounty program even better. ☕
We recently hosted a feedback session to hear their thoughts, and we’re grateful for the time and thoughtfulness they brought to the table.
Stay tuned for future updates on the M365 Bounty Program.
@eckert_madeline@nmdhkr@panther86_black@callum_infosec
As part of our Secure Future Initiative and to further the security of our customers, ourselves, and the world, today we are introducing the most transparent security research event in history: The Zero Day Quest. This new hacking event will be the largest of its kind, with an additional $4 million in potential awards for research into high-impact areas, specifically cloud and AI.
Starting today, the quest kicks off with a research challenge where vulnerability submissions in targeted scenarios are eligible for multiplied bounty awards. Submissions can also qualify researchers for a spot in the onsite hacking event in Redmond, WA, in 2025. Learn more in our blog post: https://t.co/g4vrQnymPc
#ZeroDayQuest
The Microsoft Researcher Recognition Program offers public thanks and recognition to security researchers who help protect our customers by discovering and sharing security vulnerabilities under Coordinated Vulnerability Disclosure.
Today, we are excited to recognize this year’s 100 Most Valuable Researchers (MVRs), based on the total number of points earned for each valid report. Please join us in celebrating this year’s MVRs, including our top 10:
1. 🥇 Yuki Chen @guhe120
2. 🥈Wei @XiaoWei___
3. 🥉VictorV @vv474172261
4. Suresh Chelladurai
5. Dhiral Patel @dhiralpatel94
6. Erik Donker @kire_devs_hacks
7. Nutesh Surana @_niteshsurana working with Trend Micro Zero Day Initiative @thezdi
8. Anonymous
9. Tzah Pahima @TzahPahima
10. wkai
See the full list of this year’s 100 MVRs, in addition to our Azure, Office, Windows, and Dynamics 365 leaderboards: https://t.co/MT91vHmwDt
#bugbounty #infosec
Exciting news! 📣 We’re launching the Microsoft Defender Bounty Program, offering awards up to $20,000 for identifying vulnerabilities in our Defender products and services. Learn more in our blog post: https://t.co/zbGbVM3Syp #bugbounty
Join us in celebrating a decade of global collaboration with the Microsoft Bug Bounty program! We’ve awarded over $60M to security researchers worldwide, enhancing the security of our products and services. 🎉
Learn more in our blog post: https://t.co/7GrK5yt98R
Madeline Eckert @eckert_madeline, Sr. Program Manager, MSRC, joins the Azure Security Podcast with Sarah Young @_sarahyo and Michael Howard to talk about the Microsoft Bug Bounty & Microsoft MVR programs. Tune in on Spotify: https://t.co/Zoh1TCurEa
Congratulations to all the researchers recognized in this quarter’s MSRC 2023 Q3 Security Researcher Leaderboard!
For more information, check out our blog post: https://t.co/PnYjFU4Dp5
#cybersecurity#securityresearch#bugbounty