Vulnerabilities

Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago

Over the past ten years, Microsoft has handed out $63 million in rewards as part of its bug bounty programs.

Over the past ten years, Microsoft has handed out $63 million in rewards as part of its bug bounty programs.

Microsoft on Monday announced that it has paid out $63 million in rewards to the security researchers participating in its bug bounty programs.

The tech giant launched its first bug bounty programs in 2013, when it was accepting reports of exploitation techniques in Windows 8.1 and flaws in the preview version of Internet Explorer 11.

Initially, Microsoft was receiving less than 100 reports annually, from the few dozen researchers who were participating. The company was paying a few hundred dollars in rewards annually.

Now, the company is running 17 bug bounty programs covering Azure, Edge, Microsoft 365, Windows, Xbox, and more, with rewards of up to $250,000 offered for high-impact bugs in the Hyper-V hypervisor.

According to Microsoft, thousands of security researchers from 70 countries are now receiving bug bounties. Students, academics, and full-time cybersecurity professionals are also participating in the company’s bug bounty programs.

Of the total $63 million handed out since 2013, $60 million were paid over the past five years, the company says. Starting 2020, Microsoft has been handing out more than $13 million annually to roughly 300 researchers.

“The data from the programs is a critical part of arming product and security teams across the company to deliver broader security improvements and mitigations beyond one-off bug fixes,” Microsoft says.

Since 2013, Microsoft has changed its bug bounty rewards policies several times, to offer monetary payments even for bugs that had already been discovered internally, and to make it clearer for researchers what vulnerability reports are eligible.

The award amounts were increased as well, concentrating on flaws with increased customer impact, and patching times have been shortened, the tech giant says.

Advertisement. Scroll to continue reading.

“Today, incentives and partnership are baked into our company’s vulnerability disclosure program. Every report that is triaged, assessed, and fixed is reviewed for potential bounty eligibility. There is no need to register, no need to sign up, everyone is invited,” the company notes.

Related: Microsoft Offers Up to $15,000 in New AI Bug Bounty Program

Related: Hacker Conversations: Natalie Silvanovich From Google’s Project Zero

Related: Google Announces Bug Bounty Program and Other Initiatives to Secure AI

Related Content

Malware & Threats

Patch Tuesday: Microsoft documents 60 security flaws in multiple software products and flags an actively exploited Windows zero-day for urgent attention.

CISO Strategy

Microsoft security chief Charlie Bell pledges significant reforms and a strategic shift to prioritize security above all other product features.

Malware & Threats

Researchers can earn as much as $450,000 for a single vulnerability report as Google boosts its mobile vulnerability rewards program.

Application Security

Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly.

Artificial Intelligence

Microsoft provides an easy and logical first step into GenAI for many organizations, but beware of the pitfalls.

Malware & Threats

Russia-linked APT28 deploys the GooseEgg post-exploitation tool against numerous US and European organizations.

Data Breaches

The US government says Midnight Blizzard’s compromise of Microsoft corporate email accounts "presents a grave and unacceptable risk to federal agencies."

Cloud Security

Patch Tuesday: Microsoft warns that unauthenticated hackers can take complete control of Azure Kubernetes clusters.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version