Microsoft has announced a significant expansion of its bug bounty program, now offering rewards for critical vulnerabilities found in any of its online services, regardless of whether the flaw exists in Microsoft-owned code or third-party components. This new 'in scope by default' approach was unveiled by Tom Gallagher, VP of engineering at the Microsoft Security Response Center, during Black Hat Europe. The policy shift means that all new Microsoft online services are automatically eligible for bounty awards from launch, and researchers will be compensated for impactful vulnerabilities in both Microsoft and third-party codebases, including open-source and commercial dependencies.
The change is part of Microsoft's broader Secure Future Initiative, which aims to strengthen the company's security posture amid an evolving threat landscape, particularly in cloud and AI domains. In addition to the expanded bounty program, Microsoft has recently implemented other security measures, such as disabling all ActiveX controls in Microsoft 365 and Office 2024 apps and updating security defaults to block legacy authentication methods. Over the past year, Microsoft has paid out over $17 million in bounty awards, underscoring its commitment to incentivizing security research in the highest-risk areas targeted by threat actors.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
With the new approach, Microsoft said products and online services will be considered in scope by default, including newly launched offerings, rather than waiting for separate bounty program updates. The company said it expects bounty payouts to increase as a result of the broader coverage.
At Black Hat Europe 2025, Microsoft announced that any critical vulnerability with demonstrable impact on its online services would be eligible for a bounty, regardless of whether the affected code is Microsoft-owned, third-party, or open source. The change expanded coverage to flaws in third-party dependencies and services without previously defined bounty scope.
Over the year preceding the announcement, Microsoft awarded more than $17 million to 344 security researchers through its bug bounty programs. The payout level was cited as evidence of Microsoft's continued investment in external security research.
Microsoft launched its bug bounty program in 2013, establishing a formal process to reward security researchers for reporting vulnerabilities in its products and services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcesecurityboulevard.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.