By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Microsoft broadens bug bounty scope to include any vulnerability affecting its services – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Microsoft broadens bug bounty scope to include any vulnerability affecting its services – News
News

Microsoft broadens bug bounty scope to include any vulnerability affecting its services – News

News Room
Last updated: 2025/12/13 at 10:15 PM
News Room Published 13 December 2025
Share
Microsoft broadens bug bounty scope to include any vulnerability affecting its services –  News
SHARE

Microsoft Corp. announced today that it is expanding its bug bounty program with a new policy that brings all of its online services, including those supported by third-party and open-source components, into its scope by default.

The update, introduced through a new “In Scope By Default” model, marks a significant change to Microsoft’s coordinated vulnerability disclosure ecosystem by dramatically widening what security researchers can report and be rewarded for.

Under the new framework, every Microsoft online service is now automatically eligible for bounty awards from when it launches and, in doing so, eliminates the previous requirement for product-specific scope definitions. The idea is to make participation clearer and more predictable for researchers while also ensuring that critical vulnerabilities are rewarded regardless of where they originate.

The expanded scope includes coverage for flaws in third-party libraries, dependencies or open-source packages that power Microsoft’s cloud infrastructure, not just code and software from Microsoft itself.

Tom Gallagher, vice president of engineering at Microsoft Security Response Center, noted in a blog post that expansion isn’t simply an administrative but a structural shift designed to align incentives with real-world risk. By defaulting all services into scope, Microsoft is aiming to reduce confusion, accelerate reporting and remediation and ensure that researchers can focus on vulnerabilities that have meaningful customer impact.

The change also gives Microsoft greater flexibility to collaborate with researchers on third-party or upstream vulnerabilities, including assisting in developing fixes or supporting maintainers when those flaws directly affect Microsoft services.

“If Microsoft’s online services are impacted by vulnerabilities in third-party code, including open source, we want to know,” explains Gallagher. “If no bounty award formerly exists to reward this vital work, we will offer one. This closes the gap for security research and raises the security bar for everyone who relies on this code.”

As part of the update, all new online services now fall under bounty coverage on day one, while millions of existing service endpoints no longer require manual listing or approval to qualify.

The initial reaction from security professionals has been positive. Martin Jartelius, AI product director at cybersecurity and risk management solutions provider Outpost24 AB, told News via email that “for organizations that rely on bug bounty programs to keep themselves and their customers secure, this is an important step, as it focuses on the full attack surface of an organization.”

“A very common mistake in security is the careless use of scope, or rather de-scoping, of what is included,” he said. “As Mr. Gallagher notes, attackers do not care whether they gain access through ReactToShell or a novel vulnerability in Microsoft components. Microsoft will likely find itself paying out more bounties for a while, but the resulting security improvements will ultimately be a cost-efficient way to strengthen the organization’s overall security posture.”

Image: News/Ideogram

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About News Media

News Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of News, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — News Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, News Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Best drone deal: Save  on DJI Flip (RC-N3) drone Best drone deal: Save $90 on DJI Flip (RC-N3) drone
Next Article SpaceX Quietly Removes -Per-Month Starlink Plan in the US SpaceX Quietly Removes $40-Per-Month Starlink Plan in the US
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Waymo is recalling more than 3,000 vehicles due to defective software after school bus violations
Waymo is recalling more than 3,000 vehicles due to defective software after school bus violations
News
4 Iconic Windows Apps That Quietly Faded Into History – BGR
4 Iconic Windows Apps That Quietly Faded Into History – BGR
News
A new old idea about video stores
A new old idea about video stores
News
For Making Great Coffee, Only a Certain Type of Grinder Will Do. An Expert Explains Why
For Making Great Coffee, Only a Certain Type of Grinder Will Do. An Expert Explains Why
News

You Might also Like

Waymo is recalling more than 3,000 vehicles due to defective software after school bus violations
News

Waymo is recalling more than 3,000 vehicles due to defective software after school bus violations

3 Min Read
4 Iconic Windows Apps That Quietly Faded Into History – BGR
News

4 Iconic Windows Apps That Quietly Faded Into History – BGR

8 Min Read
A new old idea about video stores
News

A new old idea about video stores

14 Min Read
For Making Great Coffee, Only a Certain Type of Grinder Will Do. An Expert Explains Why
News

For Making Great Coffee, Only a Certain Type of Grinder Will Do. An Expert Explains Why

9 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?