Microsoft paid $2.3 million to security researchers after its 2026 Zero Day Quest hacking contest produced nearly 700 submissions, including more than 80 high-impact vulnerabilities uncovered during a live event at the company's Redmond campus. Researchers from more than 20 countries tested Microsoft systems in authorized environments and reported serious cloud and AI issues such as credential exposure, SSRF chains, and cross-tenant access, with Microsoft saying customer data was not affected.
The contest forms part of Microsoft's Secure Future Initiative, launched after a U.S. government review sharply criticized the company's security culture and called for major improvements. Microsoft said it is expanding bug bounty incentives as part of that effort, citing a $5 million prize pool for the 2026 event, $1.6 million awarded after the 2025 contest, and a record $17 million paid to 344 researchers between July 2024 and June 2025; the company also highlighted growing attention to third-party code flaws in Microsoft services as part of a broader push for shared cybersecurity responsibility.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced it had awarded $2.3 million to security researchers for submissions from the 2026 Zero Day Quest contest. The payouts covered nearly 700 findings tied to cloud and AI security weaknesses.
During Microsoft's 2026 Zero Day Quest live hacking event at its Redmond campus, researchers from more than 20 countries submitted nearly 700 findings and identified more than 80 high-impact cloud and AI vulnerabilities. The flaws included credential exposure, SSRF chains, and cross-tenant access issues, all tested in authorized environments without affecting customer data.
Following its 2025 Zero Day Quest contest, Microsoft paid out $1.6 million for more than 600 submissions. The event preceded the larger 2026 contest and showed growing researcher participation.
Between July 2024 and June 2025, Microsoft paid a record $17 million to 344 researchers through its bug bounty program. This reflected a major expansion of the company's vulnerability reward efforts.
Microsoft launched its Secure Future Initiative in response to the critical review of its security practices. The program emphasized transparency and secure-by-design improvements across the company.
A U.S. Department of Homeland Security Cyber Safety Review Board report found Microsoft's security culture inadequate and in need of overhaul. The criticism later served as the catalyst for broader security changes at the company.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.