Skip to main content
CybersecurityVulnerability Management

Microsoft Boosts Bug Bounty Payouts to Record $20 Million

Diverse team of researchers and security experts gathered around a table with laptops and testing equipment.

"the growing use of AI to support security research."

That was Microsoft's own explanation for a surge in vulnerability reports that helped the company pay more than $20 million in bug bounties between July 1, 2025, and June 30, 2026 — a Redmond record in both dollars and the number of researchers rewarded.

Microsoft paid $20M to 562 researchers in the latest bounty year

Microsoft said it paid more than $20 million to 562 researchers over the 12‑month period ending June 30, 2026. By contrast, the prior year’s program paid about $17 million to 344 researchers. Microsoft called the new totals a company record. The company also reported that one element of its expansion, the Zero Day Quest challenge and live hacking event, accounted for $2.3 million in awards.

December 2025 "In Scope By Default" expansion unlocked additional rewards

Microsoft expanded its bounty program in December 2025 with a policy it calls "In Scope By Default." Under that change, critical vulnerabilities became eligible for rewards if they produced a direct and demonstrable impact on Microsoft's online services even when the faulty code originated in third‑party software or an open source project. Microsoft said the policy — introduced roughly halfway through the bounty year — accounted for $800,000 in rewards that would not previously have been available.

AI and the flood of Patch Tuesday fixes — July's 622 vulns

Microsoft attributed part of the increase in reports to an influx during the second half of the bounty year, which the company linked in part to "the growing use of AI to support security research." Microsoft also said its own use of advanced AI models has contributed to heavier Patch Tuesday outputs. July recorded 622 vulnerabilities, shattering the previous record of 206 set only a month earlier. June had itself outpaced April's 165 (previously the second‑biggest Patch Tuesday ever) and May's 137.

Days before the record‑breaking July Patch Tuesday, Microsoft's Windows + Devices vice‑president warned customers to expect more discoveries as AI plays a bigger role in vulnerability hunting both inside Microsoft and among external bounty hunters. Microsoft Executive VP of Windows + Devices Pavan Davuluri emphasized that the company offers customers an array of automated patching tools to ease the burden of those updates.

NightmareEclipse, public disclosures, and Microsoft's Digital Crimes Unit

Alongside the editorially framed AI shift, Microsoft faced a separate and more contentious problem: a prolific researcher operating under the name NightmareEclipse. The source reported unverified speculation that the researcher may be a former Microsoft staffer. NightmareEclipse published sophisticated zero‑day exploits in Q2, often shortly after Patch Tuesday, and said they wanted to cause Microsoft "maximum pain." The published flaws ranged from privilege escalation bugs leading to SYSTEM access to BitLocker bypasses.

The researcher also claimed that attempts to report vulnerabilities to Microsoft resulted in insults, humiliation, and even homelessness, and subsequently began publishing outside coordinated disclosure. That approach appeared to inspire at least two other aggrieved researchers to publish exploit code outside responsible disclosure. Microsoft responded by threatening to involve its Digital Crimes Unit in the dispute.

What this means for security teams, enterprise customers, and open‑source maintainers

  • Security teams and technologists: Expect higher volumes of discovered vulnerabilities and faster public disclosures. Microsoft links part of the increase to AI‑assisted research and to its own AI-driven discovery, which together correlate with surges in Patch Tuesday activity.
  • Enterprise customers and procurement leaders: Microsoft highlights automated patching tools as mitigation, but customers will need to plan for more frequent updates and their operational impact; the company noted these tools but did not address post‑update repair tools for devices its updates have destabilized.
  • Open‑source maintainers and third‑party vendors: The "In Scope By Default" policy makes vulnerabilities in third‑party or open‑source code that affect Microsoft services potentially eligible for bounties, increasing scrutiny on widely used dependencies and the potential for outsized attention (and reward) when direct impact on Microsoft services is demonstrated.

Microsoft's record payouts and expanded scope illustrate a market adjusting to two simultaneous forces: the commoditization of discovery through advanced tools and the policy choice to reward impact even when the underlying bug lives outside Microsoft's codebase. The company has backed that approach with money — more than $20 million and new challenge prizes — and with deterrence, by warning of Digital Crimes Unit involvement when disclosures turn public and acrimonious. The central question the facts here leave open is whether expanded rewards, automated patching, and legal pressure will together stabilize disclosure dynamics — or accelerate the next wave of public exploit drops.

Original story

Microsoft Boosts Bug Bounty Payouts to Record $20 Million | OSINTSights