Microsoft Expands Bug Bounty Program to Include Third-Party Vulnerabilities

Microsoft Expands Bug Bounty Program to Include Third-Party Vulnerabilities

First seen 11 Dec 2025, 16:52 UTC ComputerweeklyBleepingcomputerThecyberexpressTheregisterCsoonline 86% similarity 31.2

Article Content

Browse articles
ThreatCluster

Microsoft has announced an expansion of its bug bounty program to reward researchers for identifying critical vulnerabilities in any software that could impact its online services, regardless of ownership. This policy change was revealed at Black Hat Europe by Tom Gallagher, emphasizing the need to address vulnerabilities in third-party components as attackers do not differentiate between Microsoft and non-Microsoft code.

ThreatCluster AI How this analysis works

Community

Browse all →