/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says it will pay up to $26K more, an increase of 30% in some cases, in bug bounties for “high-impact” bugs in its Office 365 products

Jessica Lyons Hardcastle / The Register :

The Register Jessica Lyons Hardcastle

Context & Ripple Effects

This raise extends a decade-long ratchet in how Microsoft prices vulnerability discovery. The company has repeatedly widened the program since its 2015 bounty expansion with higher rewards and new eligible software, then partnered with HackerOne in 2019 while lifting max rewards from $15K to $50K (the HackerOne partnership).

The money involved has grown with it: $13.6M paid to 341 researchers in mid-2021, rising to $17M across 344 researchers by mid-2025. The new Office 365 premium targets the product line where Microsoft's commercial exposure is densest, and it lands alongside December's move to make critical bugs in third-party code affecting its online services eligible too.

First-order effects

  • Security researchers weighing where to spend their time now see a materially higher per-bug payoff on Office 365 specifically, tilting researcher effort toward Microsoft's cloud productivity stack.
  • Microsoft's own cost of acquiring high-impact vulnerability reports rises immediately, an explicit trade of cash for faster disclosure on products serving its enterprise base.

Second-order effects

  • Rival platform vendors running their own bounty programs face pressure to reprice high-severity cloud and productivity bugs or watch top researchers concentrate on Microsoft's higher-paying surface.
  • Brokers and gray-market buyers of Office 365 exploits lose some marginal supply to the legal channel as the legitimate price floor climbs.

Third-order effects

  • If the pattern holds — repeated raises, a broker partnership, and eligibility stretching into third-party code — bug bounties harden from PR gesture into a standing procurement channel where Microsoft effectively sets market rates for vulnerability discovery on its platforms.
  • That pricing power concentrates with whoever owns the affected product: as more critical code paths run inside hyperscaler clouds, independent researchers' economics increasingly follow each vendor's bounty schedule rather than a market-wide rate.

The trend: Microsoft is converting its bug bounty program into a primary, repriced sourcing channel for cloud-product vulnerabilities, with payouts and eligible scope expanding nearly every year.

Discussion

  • @msftsecresponse @msftsecresponse on x
    New high impact scenario awards in the Dynamics 365 and Power Platform Bounty Program and M365 Bounty Program, with awards up to $26,000 USD! For more information, check out our blog post: https://msrc-blog.microsoft.com/ ... #bugbounty