AI helps Microsoft bug hunters chase a record $20M payday
Key Points:
- Between July 1, 2025, and June 30, 2026, Microsoft paid over $20 million in bug bounties to 562 researchers, setting a new company record in both payout and number of contributors.
- The expansion of Microsoft's bug bounty program in December 2025 introduced the "In Scope By Default" policy, allowing rewards for critical vulnerabilities impacting Microsoft’s online services, including those in third-party or open source code, contributing to increased payouts.
- The surge in vulnerability reports, especially in the latter half of the year, is partly attributed to the growing use of AI in security research, with July’s 622 reported vulnerabilities shattering previous monthly records.
- Microsoft’s Executive VP of Windows + Devices acknowledged the AI-driven increase in vulnerability discoveries but emphasized the availability of automated patching tools to help customers manage the influx of updates.
- A controversial researcher known as NightmareEclipse, allegedly a former Microsoft employee, publicly released sophisticated zero-day exploits after failed attempts to report vulnerabilities through official channels, inspiring similar actions from other discontented researchers.