Microsoft announced that it is expanding its bug bounty programs, with Zero Day Quest , a new hacking event focused on finding vulnerabilities in cloud and AI products and platforms.

Microsoft Zero Day Quest invites security researchers to discover and report vulnerabilities in: AI, Microsoft Azure, Microsoft Identity, M365 and Microsoft Dynamics 365 and Power Platform. This new program allows independent security researchers to collaborate with Microsoft engineers and other researchers to share insights, learn new things, and build a secure community for everyone.
See also: Browser Company: Bug Bounty Program for Arc Browser
This challenge has two distinct opportunities:
- A Research Challenge (open to all)
- An Onsite Hacking Event (by invitation only)
The Onsite Hacking Event is an invitation-only event that automatically expands to the top 10 Microsoft researchers. An additional 45 researchers will be invited based on their submissions to the Research Challenge, which is open to all.
The Zero Day Quest started yesterday, and vulnerability submissions for specific scenarios can lead to rewards.
The Research Challenge is open to everyone and will run from November 19, 2024 to January 19, 2025.
To further promote AI security, Microsoft says it will offer double bounties for vulnerabilities related to AI products. Researchers who find these vulnerabilities will also have direct access to Microsoft AI engineers and the company's AI Red Team.
See also: Netflix: Paid out over $1 million through bug bounty
“This new hacking event will be the largest of its kind, with an additional $4 million in potential prizes, for research in high-impact areas, especially in the cloud and artificial intelligence,” said Tom Gallagher, Vice President of Engineering at the Microsoft Security Response Center (MSRC).
This is part of Secure Future (SFI), which was launched in November 2023 to strengthen cybersecurity in its products after the U.S. Department of Homeland Security said that the company's "security culture was inadequate and required review."
“Lessons learned from Zero Day Quest will be shared across Microsoft to help improve cloud and AI security“.

Bug Bounty Programs
Initiatives like Microsoft's Zero Day Quest fall into the category of Bug Bounty programs, which offer companies the opportunity to identify and fix security vulnerabilities in their systemsbefore they are exploited by malicious users. Prompt reporting leads to bug fixes and strengthens the company's protection against potential cybersecurity.
Additionally, such programs allow companies to benefit from the experience and knowledge of a wider network of cybersecurity experts. Researchers from all over the world participate and find security vulnerabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Google Bug Bounty: $10 million awarded to researchers in 2023
Many companies are now placing more and more importance on Bug Bounties, as they also improve their image in the eyes of customers and investors. They show that the company takes cybersecurity and is doing everything possible to protect its products.
Finally, these programs can be cost-effective, as companies only pay for actual findings and not for the time or effort spent searching for vulnerabilities.
Source: www.bleepingcomputer.com
