Microsoft’s Bounty Program … Improves It’s Scope?

Date:

Share post:

Careful Redmond, People Might Expect You To Improve Other Things As Well

Anyone who has dealt with Microsoft’s support services knows that there is nothing one of their reps likes more than finding a piece of third party software to blame a bug on.  If they can do so they can then close off your case immediately, leaving you to try to navigate a different support team.  Amazingly this tradition is being tossed to the wind as the Microsoft Bug Bounty program will now pay out “regardless of whether the code was written by Microsoft or a third party.“

The reasoning is that attackers don’t care who created the vulnerability, only that they can infect a Windows device with it.  This was announced yesterday at Black Hat Europe and could mean we see a lot more effective patches coming out in the future.  Microsoft have paid out over $17 million in bounty awards in the last 12 months to 344 different security researchers.  They may see that bill climb, hopefully that doesn’t change Microsoft’s mind about third party app bug bounties.

Source link

spot_img

Related articles

Sophos achieves its best-ever results in the MITRE ATT&CK Enterprise 2025 Evaluation – Sophos News

MITRE ATT&CK® Evaluations are among the world’s most rigorous independent security tests. They emulate the tactics, techniques, and...

Gemini 3 Flash is now available in Gemini CLI

Gemini 3 Flash is now available in Gemini CLI, supporting high-frequency workflows common to...

Gemini 3 Flash arrives with reduced costs and latency — a powerful combo for enterprises

Enterprises can now harness the power of a large language model that's near that of the state-of-the-art Google’s...