Microsoft paid more than $20 million in bug bounties to 562 security researchers between July 1, 2025, and June 30, 2026, according to an announcement the company made this week. The payout set a Redmond record, as did the count of those filing vulnerability reports, even though researchers had to work through a submissions process that's sometimes been frustrating. The surge reflects both expanded bounty rules and the growing role of artificial intelligence in uncovering security flaws.
The previous year's program, which itself broke company records, awarded around $17 million to 344 researchers. But Microsoft widened its bug bounty program in December 2025, switching to what it calls "In Scope By Default" — a policy that made critical vulnerabilities eligible for rewards if they showed a direct and demonstrable impact on Microsoft's online services, even when the faulty code came from a third party or an open source project. The company rolled out the policy roughly midway through the bounty year and said it accounted for $800,000 in rewards that wouldn't have been available before. Another $2.3 million came through Zero Day Quest, Microsoft's security research challenge and live hacking event.
The increased volume of reports this year can be partially explained by a noticeable influx of submissions during the second half of the year, which the company attributed in part to "the growing use of AI to support security research." Microsoft has also credited its increasingly crowded Patch Tuesdays partly to its own use of advanced AI models for vulnerability discovery. July's 622 vulnerabilities crushed the previous record of 206, set only a month earlier, while June had itself surpassed April's 165 and May's 137. Days before the record-breaking July Patch Tuesday, Microsoft's Windows + Devices veep warned customers to expect more of the same now that AI plays a big part in vulnerability discovery, both inside Microsoft and by external bounty hunters.
The explanation lies in how AI is reshaping the economics and speed of security research. Machine learning tools can now scan codebases at a pace human researchers can't match, identifying potential weaknesses in hours that might have taken weeks to spot manually. Microsoft's expanded bounty scope means more of those AI-assisted discoveries now qualify for payment, even when the vulnerable code sits outside Microsoft's own products but affects its services. The company's own AI-driven vulnerability hunting has compounded the effect, flooding Patch Tuesday schedules with fixes. However, Microsoft Executive VP of Windows + Devices Pavan Davuluri was quick to point out that the company offers customers a suite of automated patching tools to ease the burden.
Beyond navigating the rapid AI-ification of vulnerability research and the flood of reports that came with it, Microsoft has arguably faced a bigger bug problem this year amid unverified speculation that one prolific researcher may be a former Microsoft staffer. Using the name NightmareEclipse, a researcher with deep knowledge of Microsoft's software and an equally apparent disdain for the company spent the second quarter dropping sophisticated zero-days at will. NightmareEclipse claims that attempts to report vulnerabilities to Microsoft ended with them being insulted, humiliated, and left homeless, leading them to publish zero-days outside coordinated disclosure, often shortly after Patch Tuesday, saying they wanted to cause Microsoft maximum pain. These ranged from serious privilege escalation flaws leading to SYSTEM access to BitLocker bypasses, and the approach seemed to have inspired at least two other aggrieved researchers to just drop the exploit code outside of responsible disclosure. Microsoft responded by threatening to involve its Digital Crimes Unit in the dispute with NightmareEclipse, suggesting it was willing to engage law enforcement, though this went down about as well as you would expect.
The expanding role of AI in security research signals a future where vulnerability volumes will keep climbing, forcing companies to invest more heavily in both bounty programs and automated patch management systems. The NightmareEclipse episode also highlights the fragility of coordinated disclosure frameworks when researchers feel mistreated — a breakdown that can turn insider knowledge into a public threat faster than traditional security models can handle. The business calculation facing enterprises has shifted: patching cadences that were manageable a year ago may no longer keep pace with the rate at which flaws are now being discovered and disclosed. Organizations that rely on manual patch review processes will find themselves increasingly exposed as both white-hat and rogue researchers deploy machine learning to outrun traditional defenses.

