Overview
- Microsoft announced Monday that it paid more than $20 million to 562 researchers after receiving 2,531 eligible reports across 15 bug bounty programs.
- The Zero Day Quest live contest produced about 700 reports and roughly $2.3 million in awards while researchers worked directly with Microsoft security and engineering teams in Redmond.
- Microsoft said submission volume rose sharply in the second half of the year and attributed the jump in part to researchers using AI tools to discover and triage vulnerabilities.
- A researcher using the monikers Chaotic Eclipse and Nightmare Eclipse has publicly released several zero‑day details and alleges Microsoft mishandled reports, withheld payments, and deleted a reporting account, with some of those flaws later reported as exploited in the wild.
- Microsoft also expanded payments into third‑party and open‑source code programs, paying about $800,000 for those findings and issuing a single largest award of $200,000 to reflect higher top payouts and broader program scope.