Microsoft has announced a new bug bounty program focused on the artificial intelligence (AI) -powered Bing experience . Researchers will be rewarded up to $ 15,000 .

As part of this new bug bounty program for Bing, security researchers will be able to submit vulnerabilities found in the following list of services and products:
- AI-powered Bing experiences on bing.com in the browser (All major vendors supported, including Bing Chat, Bing Chat for Enterprise, and Bing Image Creator)
- AI-powered Bing integration in Microsoft Edge (Windows), including Bing Chat for Enterprise
- AI-powered Bing integration in the Microsoft Start Application (iOS and Android)
- AI-powered Bing integration in Skype Mobile Application (iOS and Android)
“Microsoft’s AI bug bounty program invites security researchers from around the world to discover vulnerabilities in the new, innovative Bing AI experience .Qualified submissions are eligible for rewards ranging from $2,000 to $15,000 USD,” Microsoft explains.
See also: Google: Expands exploit reward programs for Chrome V8, Google Cloud
“Submissions that identify vulnerabilities in Bing-related web services will be considered under the M365 Bounty Program . All submissions are reviewed for eligibility for rewards, so don't worry if you're not sure where your submission fits.“.
| Vulnerability type | Report quality | Severity | |||
| Critical | Important | Moderate | Low | ||
| Inference Manipulation | High Medium Low | $15,000 $10,000 $6,000 | $6,000 $3,000 $2,000 | $0 | $0 |
| Model Manipulation | High Medium Low | $15,000 $10,000 $6,000 | $6,000 $3,000 $2,000 | $0 | $0 |
| Inferential Information Disclosure | High Medium Low | $15,000 $10,000 $6,000 | $6,000 $3,000 $2,000 | $0 | $0 |
Additionally, researchers are encouraged to report vulnerabilities that result in:
- Changing Bing chat behavior beyond user boundaries, i.e. changing the artificial intelligence in ways that could affect all other users.
- Customize Bing chat behavior by changing the visible client and/or server configuration, including changing debug and feature flags.
- Bypassing Bing safeguards related to cross-conversation memory and history deletion.
- Disclosure of Bing's internal mechanisms and incentives, decision-making processes, and confidential information.
- Bypassing restrictions and rules in Bing chat mode sessions.
The company also listed a long list of issues and vulnerability types that are out of scope, so that researchers know what to look for.
“Collaborating with security researchers through our bug bounty programs is an essential part of Microsoft’s holistic strategy to protect customers from security threats,” said MSRC Technical Program Manager Lynn Miyashita, of the new bug bounty for Bing.
See also: AI Bing Image Generator: Blocks content related to the “Twin Towers”
“We value our collaboration with the global security research community and are excited to expand our scope to include the AI-powered Bing experience.“.
In a recent post, Microsoft said it gave out $13.8 million in rewards to 345 security researchers from around the world, who reported 1,180 vulnerabilities in 17 different bug bounty programs.
Bug Bounty programs are an emerging tool in the field of cybersecurity ,which seeks to ensure the protection of modern systems from cyberattacks. These programs, which operate on the principle of “attack to enable protection”, offer rewards for the discovery of vulnerabilities in systems.

They allow organizations to benefit from the knowledge of external and independent researchers, who identify and report vulnerabilities in their systems, earning rewards for their effort.
See also: DALL-E 3 is now available for free on Bing Chat
In other words, Bug Bounty programs are essential for ensuring cybersecurity because:
- They provide a layer of defense against attacks, filling gaps that have been ignored or misunderstood by companies' own security teams.
- They demonstrate that even the highest levels of security can be vulnerable, sending a strong message about the need for continuous improvement.
- They help businesses better understand security threats by analyzing the empirical, technical, and strategic aspects of cybersecurity.
Therefore, Bug Bounty programs, like the one for Bing, contribute significantly to cybersecurity by encouraging and motivating research.
Source: www.bleepingcomputer.com
