Microsoft joins forces with HackerOne to boost bug bounties

Security researchers will be able to get their hands on the money before they're fixed

Bug bounty

Microsoft has revamped its hacker bounty programme, following a tie-up with hacker community HackerOne.

The partnership will speed up the time it takes for security researchers and non-malicious hackers to receive their payments after uncovering flaws in the company's Cloud, Windows and Azure DevOps environments.

The use of HackerOne not only means those finding vulnerabilities will get paid faster, they'll also be able to split their bounty and donate directly to charity from their rewards.

Bounties have been increased substantially too. If someone finds a flaw as part of the Windows Insider Preview, they can now be rewarded with money pots ranging from $15,000 up to $50,000. For those finding bugs in Microsoft's Cloud Bounty programme, rewards haven't experienced such a jump, but can receive up to $20,000 for their efforts.

Another way Microsoft is ensuring those finding bugs are getting the recognition they deserve is by ensuring they're paid as soon as the vulnerability has been reproduced and assessed rather than making them wait until a fix has been developed.

If an external party uncovers a vulnerability already known to Microsoft which has been identified by an internal team the individual submitting the flaw will receive the full bounty, rather than 10% of the eligibility as was previously the case. However, anyone else finding the problem after this will still only be rewarded with the 10%.

Microsoft's bounty programmes have so far paid security researchers more than $2,000,000 to help the company improve its products and services.

"Microsoft is committed to enhancing our Bounty Programs and strengthening our partnership with the security research community, and I look forward to sharing more updates and improvements in the coming months," said Jarek Stanley, senior program manager at Microsoft.

Featured Resources

Security analytics for your multi-cloud deployments

IBM Security QRadar SIEM solution brief

Download now

Five reasons to move to the cloud

Join the enterprises moving their workloads to the cloud

Download now

Architecting hybrid IT and edge for digital advantage

Why business leaders should consider a hybrid IT strategy

Download now

Six reasons to accelerate remote asset monitoring with AI

How to optimise resources, increase productivity, and grow profit margins with AI

Download now

Recommended

Lazarus APT hacking group is targeting the defense industry
Security

Lazarus APT hacking group is targeting the defense industry

26 Feb 2021
Microsoft open sources CodeQL queries used in Solorigate inquiry
Security

Microsoft open sources CodeQL queries used in Solorigate inquiry

26 Feb 2021
CISA warns of ongoing Accellion File Transfer Appliance attacks
hacking

CISA warns of ongoing Accellion File Transfer Appliance attacks

25 Feb 2021
What is a Trojan?
Security

What is a Trojan?

25 Feb 2021

Most Popular

How to build a CMS with React and Google Sheets
content management system (CMS)

How to build a CMS with React and Google Sheets

24 Feb 2021
Oxford University COVID lab falls victim to hackers
hacking

Oxford University COVID lab falls victim to hackers

26 Feb 2021
Npower shuts down app after hackers steal user data
hacking

Npower shuts down app after hackers steal user data

25 Feb 2021