Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Paid $2,000,000 in Bounty Rewards in 2018

Microsoft says it has awarded more than $2,000,000 in bug bounty rewards to security researchers who have reported vulnerabilities via the company’s bounty program. 

Microsoft says it has awarded more than $2,000,000 in bug bounty rewards to security researchers who have reported vulnerabilities via the company’s bounty program. 

Given the success of Microsoft’s Bounty Program, the software maker has decided to bring a series of improvements to it, including faster bounty reviews and payments, broadened scope and higher awards, and a new policy for duplicate reports.

Effective January 2019, Microsoft no longer waits until a final fix has been determined to reward the reporter. Instead, it is now awarding the bounties upon completion of reproduction and assessment of each submission, so that researchers are rewarded faster. 

Microsoft says it also wants to ensure that payments happen quickly for vulnerability submissions that have successfully qualified for bounty awards. 

Thus, it is partnering with HackerOne for bounty payment processing and support. This also means support for additional payment options, including PayPal, crypto-currency, or direct bank transfer in more than 30 currencies. The HackerOne platform also has support for award splitting and charity donations. 

While Microsoft bounty awards will be processed through HackerOne, vulnerability reports should still be sent to the Microsoft Security Response Center directly, at [email protected]

Advertisement. Scroll to continue reading.

The software giant is also increasing rewards for vulnerability reports, including the top award levels for the Windows Insider Preview bounty, which were raised from $15K to $50K, and those for the Microsoft Cloud Bounty program (which includes Azure, O365, and other online services), which went from $15K to $20K. 

Microsoft also updated its policy regarding duplicates, and will pay the full eligible bounty award to the first researcher to report a bounty-eligible vulnerability, even if it is internally known. The policy regarding duplicate external reports of the same vulnerability remains unchanged. 

“Historically, external reports of internally known vulnerabilities were rewarded 10% of the eligible bounty award as the report did not inform us of a new and previously unknown issue. But understanding what external researchers are capable of discovering is valuable insight, and we want to reward researchers for their contributions whenever we can,” Microsoft says. 

Related: Microsoft Launches Azure DevOps Bug Bounty Program

Related: Zerodium Offers $500,000 for VMware ESXi, Microsoft Hyper-V Exploits

Related: HackerOne Bug Bounty Programs Paid Out $11 Million in 2017

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.