Microsoft will expand bug bounties, even in programs without official payments


  • Microsoft’s ‘In Scope by Default’ bug bounty program is now open for submissions
  • Proprietary, third-party, and open source code included.
  • Microsoft paid more than Google last year ($17 million)

Microsoft has announced a major change to the company’s bug bounty program: security researchers will now be able to submit reports of critical vulnerabilities across the company’s products and services, even when no formal bounty was previously available.

The new ‘In Scope by Default’ approach was announced by the company’s Security Response Center vice president of engineering, Tom Gallagher, at Black Hat Europe.



Leave a Comment

Your email address will not be published. Required fields are marked *