Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Paid $2,000,000 in Bounty Rewards in 2018

Microsoft says it has awarded more than $2,000,000 in bug bounty rewards to security researchers who have reported vulnerabilities via the company’s bounty program. 

Microsoft says it has awarded more than $2,000,000 in bug bounty rewards to security researchers who have reported vulnerabilities via the company’s bounty program. 

Given the success of Microsoft’s Bounty Program, the software maker has decided to bring a series of improvements to it, including faster bounty reviews and payments, broadened scope and higher awards, and a new policy for duplicate reports.

Effective January 2019, Microsoft no longer waits until a final fix has been determined to reward the reporter. Instead, it is now awarding the bounties upon completion of reproduction and assessment of each submission, so that researchers are rewarded faster. 

Microsoft says it also wants to ensure that payments happen quickly for vulnerability submissions that have successfully qualified for bounty awards. 

Thus, it is partnering with HackerOne for bounty payment processing and support. This also means support for additional payment options, including PayPal, crypto-currency, or direct bank transfer in more than 30 currencies. The HackerOne platform also has support for award splitting and charity donations. 

While Microsoft bounty awards will be processed through HackerOne, vulnerability reports should still be sent to the Microsoft Security Response Center directly, at [email protected]

The software giant is also increasing rewards for vulnerability reports, including the top award levels for the Windows Insider Preview bounty, which were raised from $15K to $50K, and those for the Microsoft Cloud Bounty program (which includes Azure, O365, and other online services), which went from $15K to $20K. 

Microsoft also updated its policy regarding duplicates, and will pay the full eligible bounty award to the first researcher to report a bounty-eligible vulnerability, even if it is internally known. The policy regarding duplicate external reports of the same vulnerability remains unchanged. 

Advertisement. Scroll to continue reading.

“Historically, external reports of internally known vulnerabilities were rewarded 10% of the eligible bounty award as the report did not inform us of a new and previously unknown issue. But understanding what external researchers are capable of discovering is valuable insight, and we want to reward researchers for their contributions whenever we can,” Microsoft says. 

Related: Microsoft Launches Azure DevOps Bug Bounty Program

Related: Zerodium Offers $500,000 for VMware ESXi, Microsoft Hyper-V Exploits

Related: HackerOne Bug Bounty Programs Paid Out $11 Million in 2017

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.