Microsoft has awarded more than $20 million to 562 security researchers through its bug bounty program, marking the largest annual payout in the company’s history.
Researchers from 64 countries reported security flaws that could have affected Microsoft customers, cloud users, businesses, and consumers worldwide.
The Microsoft Security Response Center, also known as MSRC, said the results show the value of coordinated vulnerability disclosure. Under this process, security researchers privately report weaknesses to Microsoft before attackers can exploit them.
Microsoft then investigates the issue, creates a fix, and releases security updates to protect customers. The new record is a major increase from the previous year. Microsoft paid $17 million to 344 researchers from 59 countries last year.
The latest figures show that the company is receiving more reports, rewarding more researchers, and expanding the reach of its vulnerability research programs.
Microsoft Awards $20M in Record Bounty Year
Bug bounty programs are an important part of modern cybersecurity. Independent researchers test products, services, and platforms for weaknesses that internal security teams may not find.
Their work helps companies identify risks before they become public incidents, data breaches, ransomware attacks, or zero-day exploits.
Microsoft said every valid vulnerability report allows its engineers to reduce risk before criminals can use the flaw against customers.
The company highlighted the research community’s role in securing cloud services, artificial intelligence systems, enterprise software, and consumer technologies. The growth was especially noticeable during the second half of the year, when Microsoft received a higher volume of submissions.
The company said increased researcher participation and wider use of AI tools in security research contributed to this rise. AI can help researchers review code, analyze attack paths, identify unusual behavior, and test complex systems more efficiently.
Microsoft’s Zero Day Quest event also played a key role in the record year. The live hacking event brought researchers from 20 countries to Microsoft’s Redmond campus.
Participants worked directly with Microsoft security and engineering teams to examine high-priority scenarios involving cloud and AI technologies.
During Zero Day Quest, researchers submitted nearly 700 vulnerability reports and received $2.3 million in awards. The event allowed Microsoft to collect reports rapidly while helping researchers better understand the company’s products, security priorities, and vulnerability reporting process.
Microsoft has also expanded the scope of its bounty rewards program. Eligible findings can now include certain open-source software, third-party components, and Microsoft cloud services that may not have qualified under older bounty rules.
Since this expansion, Microsoft has received more than 300 additional reports and paid over $800,000 for vulnerabilities that previously may have gone unrewarded.
According to the MSRC report, the record payout highlights the growing reliance on external security researchers as modern software environments span cloud platforms, identity systems, AI services, open-source software, and third-party dependencies.
Microsoft said finding weaknesses across its broad attack surface requires collaboration with the global security community, thanking researchers whose reports, technical expertise, and coordinated disclosures help strengthen security for billions of users worldwide.
Researchers interested in participating can learn more about Microsoft’s vulnerability rewards programs through the company’s official bug bounty portal at aka.ms/bugbounty.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year appeared first on Cyber Security News.



