Info

Microsoft launches Defender Bug Bounty Program

0

Microsoft has launched a new bug bounty program with the aim of making its Microsoft Defender-branded products and services more resilient to attack.

The Microsoft Defender Bounty Program will offer ethical hackers between $500 and $20,000 for significant vulnerabilities that have a direct and demonstrable impact on the security of its customers.

The largest sum for a novel vulnerability will go to researchers who could find critical remote code execution bugs and deliver a high-quality report.

In-scope vulnerabilities include cross-site scripting, cross-site request forgery, server-side request forgery, cross-tenant data tampering or access, and injection vulnerabilities.

As per usual, in case of multiple reports for the same vulnerability, the first submission will be considered for the reward.

The program will currently cover only Microsoft Defender for Endpoint Public APIs, which might be expanded to other offerings later.

Microsoft revealed that it paid $58.9 million in rewards to 1,147 security researchers worldwide who reported 446 eligible vulnerabilities across 22 bug bounty programs.

Just weeks before Microsoft launched a similar initiative for its AI-powered Bing experience. Microsoft also has bug bounty programs running for SharePoint, Microsoft 365, Skype for Business and on-premises Exchange.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Rhysida ransomware gang claims British Library cyberattack

Previous article

U.S. nuclear research lab breached

Next article

You may also like

More in Info

Comments

Leave a reply

Your email address will not be published. Required fields are marked *