Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Oppo announces new magnetic accessory designed to pair with Find N6 foldable phone

    Apple’s MacBook Pro 14 cannot handle the M5 Max

    Casio Edifice EQB-1300: New images of upcoming slim watch leak

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      What the polls say about how Americans are using AI

      February 27, 2026

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026
    • Business

      Salesforce tracks possible ShinyHunters campaign targeting its users

      March 15, 2026

      The team behind continuous batching says your idle GPUs should be running inference, not sitting dark

      March 13, 2026

      Met Office ‘supercomputing as a service’ one year old

      March 12, 2026

      Tech hiring evolves as candidates ask for AI compute alongside pay and perks

      March 11, 2026

      Oracle is spending billions on AI data centers as cash flow turns negative

      March 11, 2026
    • Crypto

      Banks Respond to Kraken’s Federal Reserve Access as Trump Sides with Crypto

      March 4, 2026

      Hyperliquid and DEXs Break the Top 10 — Is the CEX Era Ending?

      March 4, 2026

      Consensus Hong Kong 2026: The Institutional Turn 

      March 4, 2026

      New Crypto Mutuum Finance (MUTM) Reports V1 Protocol Progress as Roadmap Enters Phase 3

      March 4, 2026

      Bitcoin Short Sellers Caught Off Guard in New White House Move

      March 4, 2026
    • Technology

      Oppo announces new magnetic accessory designed to pair with Find N6 foldable phone

      March 15, 2026

      Apple’s MacBook Pro 14 cannot handle the M5 Max

      March 15, 2026

      Casio Edifice EQB-1300: New images of upcoming slim watch leak

      March 15, 2026

      Save 90% on Microsoft Visual Studio Pro 2026

      March 15, 2026

      One powerful Microsoft tool to organize every task, deadline, and deliverable — now a flat $45

      March 15, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Microsoft expands bug bounty scheme to include third-party software
    Technology

    Microsoft expands bug bounty scheme to include third-party software

    TechAiVerseBy TechAiVerseDecember 11, 2025No Comments5 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Microsoft expands bug bounty scheme to include third-party software
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Microsoft expands bug bounty scheme to include third-party software

    The company is to offer bug bounty awards for people who report security vulnerabilities in third-party and open source software impacting Microsoft services

    By

    • Bill Goodwin,
      Investigations Editor

    Published: 11 Dec 2025 12:15

    Microsoft is to expand its bug bounty scheme to reward people for finding high-risk security vulnerabilities that could impact the security of Microsoft’s online services.

    The company is extending its reward programme to cover vulnerabilities in software that could affect services provided by the company, irrespective of whether it is owned and managed by Microsoft.

    Microsoft awarded more than $17m to security researchers through its bug bounty programmes and live hacking events this past year, and expects to offer more in 2026.

    The Redmond-based company said the programme, dubbed “in scope by default”, will extend its bug bounty scheme to include serious vulnerabilities that affect Microsoft cloud services.

    It will offer bounties for third-party and open source code in cases where there is no existing bug bounty programme available, if they have an impact on Microsoft’s online products.

    Microsoft claimed it “would do whatever it takes” to ensure that bugs in open source and third-party software are fixed. “This could be writing patches or offering support to help the code owner address,” it said. “The level of support will depend on what is needed on a case-by-case basis.”

    Until now, Microsoft has focused its vulnerability research on product-focused bug bounty programmes.

    The new bounty programme will take a “holistic approach”, reflecting the ways that hostile hackers find to attack systems, which often involves finding vulnerabilities between the boundaries of different software products.

    Tom Gallagher, vice-president for Microsoft Security Response Centre, said the change will ensure there are stronger protections against vulnerabilities in supply chains that can be used by attackers to “pivot” into high-value targets.

    Microsoft’s approach is to use bug reports, not simply for the sake of fixing bugs, but as a red flag to identify areas where Microsoft may need to devote additional security resources, he told Computer Weekly.

    Microsoft has been criticised by security researchers for “unacceptable delays” in fixing serious vulnerabilities in its Azure cloud platform and for botching one security patch that was later exploited by Chinese spies.

    Gallagher said the company had become more transparent about security over the past 12 months. This includes posting CVE reports about software vulnerabilities discovered in its cloud services, which were previously not publicly disclosed as they were automatically patched by Microsoft.

    “Microsoft was the first cloud provider to say, hey, if there is a critical issue in the cloud, even if you don’t need to patch it, we are going to issue that CVE,” he said. “And we do that for issues that security researchers report.”

    About half of the CVEs are discovered by Microsoft’s own security specialists.

    The value of vulnerabilities

    The company takes several factors into account when deciding how much to pay out for a vulnerability, and will offer more to encourage people to look for bugs in key areas.

    Microsoft’s Hyper V, a tool used to isolate virtual machines in Windows and on Microsoft Azure, is a priority, attracting up to a quarter of a million dollars for one vulnerability.

    Gallagher told Computer Weekly that since he joined Microsoft in 1999, it has become much harder for security researchers and bad actors to find security vulnerabilities in Microsoft software.

    “In a modern system, you are going to have to work pretty hard to find that initial bug, and in order to build a full exploit, you will often need a chain of vulnerabilities that are perfectly aligned,” he said.

    Using AI to find bugs

    The company is also looking at how artificial intelligence (AI) can be used to automate the finding of vulnerabilities. “It is in the very early stages,” said Gallagher. “It’s looking very fruitful, and I am excited about that.”

    He said AI can be trained to understand complex systems and will be able to find vulnerabilities at a scale that humans cannot match.

    “For a company like us, its super valuable because we can find a bunch of issues very quickly,” said Gallagher. “You can also imagine bringing it to the next step where you are also using it to fix issues and to mitigate issues.”

    He added that in the future, there will be more focus on probing the security of large language model AI systems. Unlike traditional security vulnerability research, that will not necessarily need people with strong technical skills.

    “If you are a good con man, or a social engineer, or you are just savvy with how to talk to someone, you don’t need to have that technical expertise,” said Gallagher.

    He added that Microsoft runs programmes to encourage security researchers to go bug hunting and develop the skills of young people interested in security vulnerability research.

    They include a series of Blue Hat conferences in Redmond, Israel and India, for people who are starting out careers in security research. “We want to bring them in early and help them understand how they can leverage some of those basic skills,” said Gallagher.

    Read more on Business applications


    • Why bug bounty schemes have not led to secure software

      By: Bill Goodwin


    • Microsoft to offer hackers millions in Zero Day Quest event

      By: Alexander Culafi


    • Salesforce helps customers establish bug bounty programmes

      By: Alex Scroxton


    • Salesforce’s bug bounty programme paid out $3m in 2023

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleGoogle DeepMind partners with UK government to deliver AI
    Next Article AI drives storage array makers to embrace data management
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Oppo announces new magnetic accessory designed to pair with Find N6 foldable phone

    March 15, 2026

    Apple’s MacBook Pro 14 cannot handle the M5 Max

    March 15, 2026

    Casio Edifice EQB-1300: New images of upcoming slim watch leak

    March 15, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025718 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025305 Views

    Wired Headphones Are Making A Comeback, And We Have Gen Z To Thank

    July 22, 2025213 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025178 Views
    Don't Miss
    Technology March 15, 2026

    Oppo announces new magnetic accessory designed to pair with Find N6 foldable phone

    Oppo announces new magnetic accessory designed to pair with Find N6 foldable phone – NotebookCheck.net…

    Apple’s MacBook Pro 14 cannot handle the M5 Max

    Casio Edifice EQB-1300: New images of upcoming slim watch leak

    Save 90% on Microsoft Visual Studio Pro 2026

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Oppo announces new magnetic accessory designed to pair with Find N6 foldable phone

    March 15, 20264 Views

    Apple’s MacBook Pro 14 cannot handle the M5 Max

    March 15, 20264 Views

    Casio Edifice EQB-1300: New images of upcoming slim watch leak

    March 15, 20265 Views
    Most Popular

    Bench is charging people for services they already paid for, some customers say

    March 15, 20250 Views

    Major strike by Fujitsu staff at ‘cash cow’ HMRC

    March 15, 20250 Views

    These Laptop Stands Run My Household, and Life Is Better for It

    March 16, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.