Skip to main content
  1. Home
  2. Computing
  3. News

Microsoft’s bug bounty system now offers up to $15,000 for finding Windows flaws

Add as a preferred source on Google

Microsoft has expanded its existing bug bounty system to include all manner of Windows flaws if they are found within one of its slow ring Insider builds. Whether you find them in the base operating system itself, or any of its companion software pieces, you may now be able to claim a finder’s fee reward from Microsoft up to $15,000, Ars Technica reports

Bug bounty systems are a tried-and-tested formula for finding bugs before they can see wider exploitation. It turns the practice of discovering flaws into a money-making endeavor, rather than the exploitation of them. Microsoft has seen much success with bounties for the Edge browser, and exploit-mitigation systems.

Recommended Videos

It’s now added an ongoing bounty offering of up to $15,000 for “critical and important vulnerabilities” discovered in the slow ring Windows Insider preview builds. This represents the most general bounty scheme that Microsoft has yet launched and opens the door to a wider range of exploits to be discovered.

As much as digging for bugs in Windows Insider builds would be a decent way to earn a living for a number of hackers, regardless of the color hat they wear, Microsoft’s older, more selective bounty systems are still far more lucrative. One key area Microsoft is looking to shore up is its virtual machine Hyper-V system. Find a flaw in that and Microsoft could reward you up to $250,000, whether it is for Windows 10, Server 2012 or a Windows Server Insider preview.

Problems found with the Windows Defender Application Guard come with a $30,000 bounty attached, whereas mitigation bypass bugs could net you as much as $100,000 if discovered. In total there are eight ongoing bug bounty schemes, some of which have been in operation for as long as four years.

The reward figures listed are the maximum, however, so most bugs will unlikely earn that much. The smallest payout for any category is $500, so don’t expect to retire if you find a singular flaw in a piece of Microsoft software. The potential is there, though, if your detection skills are strong enough.

You have time to find them too, as most crucially, the new bounties are not time-limited. While in the past the software giant often pushed for bugs to be found within a select time period to help clear up software before launch, with its new bounties it has them all listed as “ongoing,” with no stated plan for finalizing them.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
The Mac Pro nearly received an M3 Extreme chip twice as powerful as M3 Ultra
High production costs likely killed Apple’s M3 Extreme plans
Apple's Mac Pro on a table at a press event.

Apple discontinued the Mac Pro earlier this year, ending a 20-year run for a computer that once represented the very best of the company’s desktop lineup. However, Apple reportedly had much bigger plans for the machine before ultimately replacing it with the Mac Studio.

According to Bloomberg’s Mark Gurman, Apple developed an M3 Extreme chip that could have offered twice as many CPU and GPU cores as the M3 Ultra. The processor was intended to sit above the Ultra tier and could have finally given the Mac Pro the performance advantage it badly needed. Apple eventually abandoned the chip due to concerns over production costs and limited demand for such an expensive machine.

Read more
Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
Researchers discover AI attack that rewrites an assistant's long-term memory
Chatbot on a smartphone.

Large language models are getting better at remembering us. Whether it's your preferred writing style, recurring tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more personal and useful. But according to new research, that same feature could become one of AI's biggest security vulnerabilities.

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, capable of secretly planting false memories inside AI agents. Rather than stealing information outright, the attack manipulates what an AI remembers, potentially causing it to make dangerous decisions long after the original attack has taken place.

Read more
This experiment shows how easy it is to poison an open-weight AI model for under $100
This research raises new doubts about trusting open weight AI models.
Computer, Electronics, Laptop

Open-weight AI models have been having a moment lately. Just this month, Moonshot's massive Kimi K3 model landed close behind Claude Fable 5 and GPT 5.6 Sol in several benchmarks, all while remaining fully open-weight and downloadable by anyone.

However, Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, managed to poison an open-weight model and proved how easily that openness can be turned against you (via The Register).

Read more