Briev
Live
Technology

Microsoft's bug bounty hits $20 million record as AI fuels surge in reports

Microsoft disclosed that it paid over $20 million to 562 security researchers between July 2025 and June 2026, the highest payout in its history, driven by an expanded bounty scope and AI-assisted vulnerability discovery.

During the fiscal year ending June 2026, Microsoft paid more than $20 million to 562 bug hunters, surpassing the previous year’s $17 million to 344 researchers. The increase follows a December 2025 policy change that automatically includes critical vulnerabilities impacting Microsoft’s online services, regardless of the code’s origin, contributing roughly $800,000 in new rewards. An additional $2.3 million was distributed through the Zero Day Quest live hacking event.

Microsoft attributed the surge in reports to the expanding role of artificial-intelligence models in both its internal security work and external researcher submissions, which helped produce a July Patch Tuesday with 622 vulnerabilities, far above earlier monthly totals. Executive Vice President of Windows + Devices Pavan Davuluri warned customers that AI-driven discovery will likely keep Patch Tuesdays busy, while also noting the availability of automated patching tools. The company faced a contentious episode with a researcher using the handle NightmareEclipse, who released zero-days after alleged mistreatment, prompting Microsoft to threaten involvement of its Digital Crimes Unit.

Why it matters

The record bounty payout shows how AI is reshaping vulnerability research and how major tech firms are adapting their security incentives.

In this story

bug bountyAI-assisted securityIn Scope By DefaultZero Day QuestPatch Tuesdayvulnerability rewardsdigital crimes unit