A record-breaking year for Microsoft's Bounty Programs!
This year, Microsoft awarded more than $20 million to 562 security researchers, the highest total payout and largest number of researchers recognized in program history.
Read the full blog to learn more about the impact of the global security research community: https://t.co/nrkGap6nDi
We’ve updated the Microsoft 365 Insider Builds on Windows Bounty Program to better recognize impactful research and improve the submission experience for our community.
What’s new:
• Added Information Disclosure as an eligible impact category
• Increased awards for Security Feature Bypass to align with top General Award levels
• Introduced three new high‑impact scenarios, with awards of $30K, $20K, and $20K
• Maintained the $30K award for unauthenticated, non‑sandboxed code execution with no user interaction
These updates reflect feedback from researchers and help ensure the program continues to reward high‑impact research while strengthening protections for customers.
Learn more: https://t.co/004b58RxFj
Kicking off the Call for Papers for BlueHat Redmond ⚽️
BlueHat brings together security researchers and responders to exchange ideas, experiences, and best practices. We’re looking for talks covering vulnerability research, mitigations, emerging threats and techniques, and more.
Bring your best ideas, because security is a team sport.
Submit your paper by February 28, 2026: https://t.co/exQyHksHTo
Join the Microsoft Security Response Center (MSRC) for our Researcher Celebration at Black Hat Europe on Wednesday, December 10, from 4:30–9:00 PM.
This event honors the contributions of the global security research community. Connect with peers, celebrate achievements, and enjoy networking with researchers from around the world.
Apply to attend now: https://t.co/6adjtXT2JV
#BHEU
Join MSRC on September 17 for a 30-minute conversation with Pushkar Saraf, Director of Security, Microsoft AI. He’ll share how he approaches security research, from spotting opportunities to the techniques and workflows that drive real-world results. Expect practical insights, lessons from the field, and a moderated Q&A to dive deeper into the discussion.
Whether you're new to security research or looking to sharpen your skills, this session offers a look into the workflows, challenges, and creative problem-solving that drive impactful findings.
Register now: https://t.co/N3BsFovNRk
#ZeroDayQuest
The Microsoft Researcher Recognition Program offers public thanks and recognition to security researchers who help protect our customers by discovering and sharing security vulnerabilities under Coordinated Vulnerability Disclosure.
Today, we are excited to recognize this year’s 100 Most Valuable Researchers (MVRs), based on the total number of points earned for each valid report. Please join us in celebrating this year’s MVRs, including our top 10:
1. 🥇 VictorV (@vv474172261)
2. 🥈 wkai
3. 🥉 Suresh Chelladurai
4. Anonymous
5. Adnan (@adnanthekhan)
6. Dhiral Patel (@dhiralpatel94)
7. Nan Wang (@eternalsakura13) and Ziling Chen
8. Anonymous
9. @0x140ce
10. Azure Yang (@4zure9)
See the full list of this year’s 100 MVRs, in addition to our Azure, Office, Windows, and Dynamics 365 leaderboards: https://t.co/8vhDhDpr3E
#bugbounty
We're now offering bounty awards up to $30,000 for AI vulnerabilities in Dynamics 365 and Power Platform.
Eligible vulnerability types are defined in the Microsoft Vulnerability Severity Classification for AI Systems (https://t.co/Evzy41F1f2) and include:
• Inference manipulation
• Model manipulation
• Inferential information disclosure
Your research could help us strengthen the security of enterprise AI. Learn more: https://t.co/6fhQbwL0e2.
Earlier this month, we hosted the Microsoft Zero Day Quest, the largest live hacking event of its kind. This inaugural event brought together top security researchers from around the world to find the highest-impact vulnerability scenarios in Microsoft Copilot and Cloud.
The result? More than 600 vulnerabilities submitted and $1.6 million awarded, with additional findings still under review.
We're also making two major commitments moving forward:
1. Continuing the 100% AI bounty award multiplier
2. The Microsoft Zero Day Quest will be an annual event
This is just one part of Microsoft’s broader bug bounty program, which awarded over $16 million in 2023. We're proud to work with the global research community to help secure the future—by design, by default, and in operation.
Read more in our blog post by Tom Gallagher (@secbughunter), VP of Engineering, Microsoft Security Response Center: https://t.co/2c7RDySWch
If you missed yesterday’s session on security research in Copilot Studio, it’s not too late! The full recording is available now on YouTube. Catch Scott Gorlick share his expertise on leveraging the Copilot ecosystem for enhanced security research: https://t.co/V1nNzp9eVN
We’re excited to announce the scope of the Microsoft AI Bounty Program has expanded to include new vulnerability types for Critical and Important cases, with awards up to $30,000.
New vulnerability types:
- Deserialization of Untrusted Data
- Injection (Code Injection)
- Authentication Issues
- Injection (SQL Injection and Command Injection)
- Server-Side Request Forgery (SSRF)
- Improper Access Control
- Cross Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Web Security Misconfiguration
- Cross Origin Access Issues
- Improper Input Validation
Learn more on the AI Bounty Program page: https://t.co/04dRjyIrFv
Are you a security researcher interested in AI bounty submissions? Join us to learn more about Microsoft's Bug Bounty Program and how to qualify for the Zero Day Quest. In this session, hosted by Lynn Miyashita (@lynnfosec) and Andrew Paverd (@ajpaverd), we'll discuss Microsoft's approach to bug bounties and deep dive into the new vulnerability categories for AI security research.
Don't miss out! Join us on December 17th at 9:30 AM PT for a virtual training session. Register now: https://t.co/hfLuBY5aj2
#ZeroDayQuest
As part of our Secure Future Initiative and to further the security of our customers, ourselves, and the world, today we are introducing the most transparent security research event in history: The Zero Day Quest. This new hacking event will be the largest of its kind, with an additional $4 million in potential awards for research into high-impact areas, specifically cloud and AI.
Starting today, the quest kicks off with a research challenge where vulnerability submissions in targeted scenarios are eligible for multiplied bounty awards. Submissions can also qualify researchers for a spot in the onsite hacking event in Redmond, WA, in 2025. Learn more in our blog post: https://t.co/g4vrQnymPc
#ZeroDayQuest
Thank you to everyone who attended the MSRC Researcher Celebration at #BHUSA last night. Your commitment to "Security Above All Else" is what drives our community forward. We hope you had the opportunity to network, learn, and connect with others who share your passion. A special shoutout to our 2024 MSRC MVRs for being part of this incredible event. Together, we’re building a stronger, more secure future!
#MSFTBlackHat
@sherrod_im Lynn Miyashita & Andrew Paverd also talk about what defines an AI bug, and the potential for finding vulnerabilities that span the traditional scope of a bug hunter and new vulnerabilities that may arise because of AI. Details on the bounty program here: https://t.co/SsfEsyzfuA
🚨 Attention security researchers, responders, and everyone in the security community! 🚨
The #BlueHat 2024 Call for Papers is now open! We invite everyone to submit proposals for 45-minute Breakout Sessions or 15-minute Lightning Talks. Don’t miss this opportunity to share your findings, new ideas, and best practices at BlueHat 2024, October 29-30, in Redmond, WA. Learn more in our blog post: https://t.co/8ZwWhytef7
We’re excited to announce that the Microsoft Bounty Program has awarded $16.6M in bounty awards to 343 security researchers from 55 countries over the past year. Each year, we identify over a thousand potential security issues together, safeguarding our customers from possible threats through the Microsoft Bounty Program. Learn more: https://t.co/amDwKzgprf
#bugbounty #infosec
The Microsoft Researcher Recognition Program offers public thanks and recognition to security researchers who help protect our customers by discovering and sharing security vulnerabilities under Coordinated Vulnerability Disclosure.
Today, we are excited to recognize this year’s 100 Most Valuable Researchers (MVRs), based on the total number of points earned for each valid report. Please join us in celebrating this year’s MVRs, including our top 10:
1. 🥇 Yuki Chen @guhe120
2. 🥈Wei @XiaoWei___
3. 🥉VictorV @vv474172261
4. Suresh Chelladurai
5. Dhiral Patel @dhiralpatel94
6. Erik Donker @kire_devs_hacks
7. Nutesh Surana @_niteshsurana working with Trend Micro Zero Day Initiative @thezdi
8. Anonymous
9. Tzah Pahima @TzahPahima
10. wkai
See the full list of this year’s 100 MVRs, in addition to our Azure, Office, Windows, and Dynamics 365 leaderboards: https://t.co/MT91vHmwDt
#bugbounty #infosec
Congratulations to all the researchers recognized in this quarter’s MSRC 2023 Q4 Security Researcher Leaderboard! 🎉
For more information, check out our blog post: https://t.co/0mJBDzdFpK
#cybersecurity#securityresearch#bugbounty
Join us in celebrating a decade of global collaboration with the Microsoft Bug Bounty program! We’ve awarded over $60M to security researchers worldwide, enhancing the security of our products and services. 🎉
Learn more in our blog post: https://t.co/7GrK5yt98R