Microsoft Boosts Bug Bounty: Now Offering $30,000 for Critical AI Vulnerabilities


# Microsoft Boosts Bug Bounty Rewards for AI Vulnerabilities

Microsoft has increased bug bounty payouts to $30,000 for AI vulnerabilities discovered in its Dynamics 365 and Power Platform services. The enhanced program targets security flaws in business-critical applications that help organizations analyze data, automate processes, and connect various business operations.

Researchers can earn rewards for identifying three specific types of AI vulnerabilities:
– Inference manipulation
– Model manipulation
– Inferential information disclosure

To qualify for the bounty, vulnerabilities must be classified as Critical or Important severity according to Microsoft’s Vulnerability Severity Classification for AI Systems and must be reproducible in the specified products.

“We invite individuals or organizations to identify security vulnerabilities in targeted Dynamics 365 and Power Platform applications and share them with our team,” Microsoft stated. While standard AI bounty awards range from $6,000 to $30,000, higher rewards are possible based on impact, severity, and submission quality.

This enhancement follows Microsoft’s Zero Day Quest launched during last year’s Ignite conference, which focused on cloud and AI security. The company recently revealed it paid over $1.6 million to researchers for more than 600 vulnerability submissions during this initiative.

“Nearly 100 researchers also participated in our training sessions, which included AI bug hunting with our AI Red Team, SSRF training with our engineering team, and tips and advice from the bounty team,” said Tom Gallagher, Vice President of Engineering at Microsoft Security Response Center.

Earlier this year, Microsoft also increased payouts for moderate severity Microsoft Copilot vulnerabilities and implemented a 100% award multiplier for all Copilot bounty awards to encourage AI security research.

Share This Article