Microsoft will expand bug bounties – even on programs without official payouts


  • Microsoft’s ‘In Scope by Default’ bug bounty program is now open for submissions
  • Proprietary, third-party, and open source are all included
  • Microsoft paid out more than Google last year ($17 million)

Microsoft has announced an important change to the company’s bug bounty program – security researchers will now be eligible to submit critical vulnerability reports across all of the company’s products and services, even where no formal bounty was available before.

The new ‘In Scope by Default’ approach was announced by the company’s Security Response Centers Engineering VP, Tom Gallagher, at Black Hat Europe.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top