HomeSecurityMicrosoft bug bounty 2020-2021: How much money have researchers earned?

Microsoft bug bounty 2020-2021: How much money have researchers earned?

Microsoft has revealed that it paid out a total of $13.6 million to 341 security researchers as part of its bug bounty programslast year. The company has been giving out large sums of money to researchers to reward them for uncovering various vulnerabilities in Microsoft products.

See also: Microsoft bonus: $1,500 to employees for "withstanding" the pandemic!

Microsoft bug bounty

The $13.6 million in rewards were given from July 1, 2020, to June 30, 2021 , and are slightly lower than those paid by the company in 2019.

The largest reward was $200,000 and was given as part of the Hyper-V Bounty Program. This is Microsoft's bug bounty program for its virtualization layer in Windows 10, Windows Server 2016, and containers for running Windows and Linux applications in the cloud.

See also: Hacker won $2 million in bug bounty programs!

The average reward across all Microsoft bug bounty programs is $10,000. According to a post from the Microsoft Security Response Center (MSRC), the huge number of vulnerability reports from security researchers reflects “the talent and creativity of the global research community and their invaluable collaboration in addressing the challenges of an ever-changing security environment.”

Microsoft has launched a few new bug bounty programs this year, including one for Microsoft Teams with prizes of up to $30,000 for critical bug reports. Another new bounty program is targeting a potential future post-quantum cryptography standard, called Supersingular Isogeny Key Encapsulation (SIKE).

Microsoft bug bounty 2020-2021: How much money have researchers earned?

Microsoft has 17 bug bounty programsthat allow security researchers to find and disclose vulnerabilities and receive handsome rewards. The Hyper-V program offers the largest prize (up to $250,000).

See also: GitHub bug bounty: Researchers' rewards reach $1.5 million

The Microsoft Identity bounty is also significant, covering Microsoft Account, Azure Active Directory, selected OpenID standards. The top reward is $100,000.

Many companies have bug bounty programs, as they have proven to be very effective. Through them, companies can fix their products, since they have the opportunity to collaborate with great security researchers. Some researchers have even managed to earn millionsby revealing vulnerabilities in bug bounty programs.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS