/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft expands its Bug Bounty schemes with higher rewards, bonuses, and new eligible software

Microsoft Bounty Programs Expansion - Bounty for Defense, Authentication Bonus, and RemoteApp  —  I am very pleased to be releasing additional expansions of the Microsoft Bounty Programs.

Microsoft Security Response Center Jason Shirk

Context & Ripple Effects

This 2015 expansion is an early data point in what became a decade-long ratchet at Microsoft: each few years the company raises reward ceilings, adds bonus categories, or widens eligible software. The pattern runs from the 2015 authentication bonus and RemoteApp coverage through the HackerOne partnership and faster payouts in 2019, to the 2022 decision to pay up to $26K more for high-impact Office 365 bugs.

What makes the arc notable is scale: by mid-2025 Microsoft was reporting $17M paid to 344 researchers across 59 countries, and in late 2025 it extended eligibility to critical vulnerabilities in third-party code touching its online services. The 2015 move — higher rewards plus new software categories — is the template those later steps iterate on.

First-order effects

  • Security researchers gain higher potential payouts for Microsoft vulnerabilities, with a new authentication bonus steering effort toward identity and access bugs, and RemoteApp added as newly eligible attack surface.

Second-order effects

  • Rival platform vendors face pressure to match rising reward ceilings or lose researcher time, since independent hackers allocate effort toward whichever program pays best per bug found.

Third-order effects

  • If the ratchet holds, external bounty programs harden into a permanent procurement channel for security work — with scope eventually covering third-party code embedded in a vendor's services, as Microsoft's own later expansion shows.

The trend: Corporate bug bounty programs are escalating from ad-hoc rewards into large-scale, continuously raised vulnerability procurement, with Microsoft repeatedly resetting the ceiling.