MICROSOFT has disclosed that it paid over $20 million through its bug bounty programs in the past year, with 2,531 eligible reports submitted by researchers from 64 countries. The payouts included $2.3 million from the Zero Day Quest hacking contest and $800,000 for initiatives targeting vulnerabilities in third-party code. The company noted a notable increase in report submissions, attributed to heightened engagement and the use of AI in security research.
However, not all researchers are satisfied; some, like the researcher known as Chaotic Eclipse, have criticized Microsoft for mishandling reports and communication.