/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft expands its bug bounty program so that any critical vulnerability, including in third-party code, impacting its online services is eligible for awards

Duncan Riley / SiliconANGLE :

SiliconANGLE Duncan Riley

Context & Ripple Effects

Microsoft has repeatedly widened bounty coverage, from broader eligible software in its earlier bounty-program expansion to a dedicated Xbox program. The latest change extends that progression to the dependency code behind online services.

The program is already operating at meaningful scale: Microsoft recently reported payments to hundreds of researchers across dozens of countries. Treating third-party flaws as in-scope ties that researcher network more directly to service reliability.

First-order effects

  • Security researchers can seek awards for critical flaws in third-party code when those flaws affect Microsoft online services, expanding the set of reportable findings.
  • Microsoft must assess and coordinate remediation for qualifying dependency vulnerabilities affecting its services, rather than limiting bounty handling to code it directly develops.

Second-order effects

  • Third-party software suppliers whose components underpin Microsoft services may face more vulnerability reports and faster pressure to provide fixes or mitigations.
  • The expanded scope makes bounty researchers a more direct source of supply-chain security testing for cloud-service operators, alongside their testing of first-party code.

Third-order effects

  • If other service operators adopt similar rules, accountability for production security could shift further from code ownership toward the company operating the customer-facing service.
  • This approach may make coordinated disclosure across software dependencies a more central part of bug-bounty design, though its effectiveness will depend on triage and vendor-response capacity.

The trend: Bug bounties are evolving from product-focused reward programs into a mechanism for finding and coordinating risk across the full software supply chain behind online services.

Discussion

  • @smaury92 @smaury92 on x
    Interesting move by @msftsecresponse, I hope this sets a trend in the industry! https://www.microsoft.com/... [image]
  • @i_am_jakoby @i_am_jakoby on x
    I got microsoft to change their whole bounty program! they finally listened. critical vulns now count even if they're “out of scope”, as long as they impact microsoft's ecosystem. Pictured below is the exact post to make it happen. We have been having very respectful [image]
  • @msftsecresponse @msftsecresponse on x
    As announced by Tom Gallagher (@secbughunter), VP of Engineering, MSRC, on stage at Black Hat Europe, we're evolving our bug bounty program. Now, high-severity vulnerabilities that directly impact Microsoft online services are eligible for bounty awards, whether the code is [imag…