Security News

Microsoft Pays Out $20 Million to Security Researchers in Bug Bounty Program

Security Week · 4 Aug 2026
Key Takeaway Keep your Microsoft software and systems updated promptly, as patches often fix vulnerabilities discovered through programs like this one.

Microsoft has revealed that it paid out $20 million to more than 500 security researchers through its bug bounty program between July 1, 2025, and June 30, 2026. The largest single reward paid during this period was $200,000, highlighting the value Microsoft places on identifying and fixing serious security flaws before they can be exploited by attackers.

Bug bounty programs like Microsoft's incentivise independent researchers to responsibly report software vulnerabilities directly to the company, rather than selling them on the black market or exploiting them for malicious purposes. This approach helps large technology providers strengthen their products and reduce the risk of cyberattacks affecting the millions of businesses and individuals who rely on their software.

While small businesses don't run their own bug bounty programs, they benefit indirectly from these efforts. Vulnerabilities patched thanks to researcher disclosures reduce the number of exploitable weaknesses in widely used software like Windows and Microsoft 365, which many Australian SMBs depend on daily.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.