{"id":45446,"date":"2026-04-16T01:12:00","date_gmt":"2026-04-15T17:12:00","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/16\/microsoft-pays-2-3m-for-cloud-and-ai-flaws-at-zero-day-quest\/"},"modified":"2026-04-16T01:12:00","modified_gmt":"2026-04-15T17:12:00","slug":"microsoft-pays-2-3m-for-cloud-and-ai-flaws-at-zero-day-quest","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/16\/microsoft-pays-2-3m-for-cloud-and-ai-flaws-at-zero-day-quest\/","title":{"rendered":"Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest"},"content":{"rendered":"\n<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/10\/04\/Microsoft.jpg\" width=\"1600\" alt=\"Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest\"><\/p>\n<p>Microsoft has awarded $2.3 million to security researchers after receiving nearly 700 submissions during this year&#8217;s&nbsp;Zero Day Quest hacking contest.<\/p>\n<p>Tom Gallagher, Vice President of Engineering at Microsoft Security Response Center (MSRC), said that over 80 flaws found during the live event at Microsoft&#8217;s Redmond campus were high-impact cloud and AI security vulnerabilities.<\/p>\n<p>&#8220;During the 2026 live hacking event, Microsoft partnered with the global security research community, representing more than 20 countries and a wide range of professional backgrounds, from high school students to college professors,&#8221; <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/blog\/2026\/04\/zero-day-quest-2026-over-2-million-awarded-vulnerability-research\" target=\"_blank\" rel=\"nofollow noopener\">Gallagher said<\/a>.<\/p>\n<p>&#8220;Researchers conducted all testing within authorized environments in accordance with Microsoft&#8217;s Rules of Engagement, demonstrating potential impact without accessing customer data or other tenant systems. Within these constraints, researchers identified critical paths involving credential exposure, SSRF chains, and cross&#8209;tenant access.&#8221;<\/p>\n<p>Last August, Microsoft announced that it <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-announces-5-million-prize-pool-for-zero-day-quest-hacking-contest\/\" target=\"_blank\" rel=\"nofollow noopener\">would increase the prize pool<\/a> at this year&#8217;s Zero Day Quest hacking contest to $5 million in bounty awards, which the company described as the &#8220;largest hacking event in history.&#8221;<\/p>\n<p>The 2025 Zero Day Quest also generated significant participation from the security community, following Microsoft&#8217;s <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-launches-zero-day-quest-hacking-event-with-4-million-in-rewards\/\" target=\"_blank\" rel=\"nofollow noopener\">offer of $4 million<\/a> in rewards for vulnerabilities in cloud and AI products and platforms.<\/p>\n<p>After the hacking competition concluded, Microsoft announced it had <a href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/04\/zero-day-quest-2025-1.6-million-awarded-for-vulnerability-research\/\" target=\"_blank\" rel=\"nofollow noopener\">paid $1.6 million in rewards<\/a> after receiving more than 600 vulnerability submissions.<\/p>\n<p>The Zero Day Quest contest is part of Microsoft&#8217;s Secure Future Initiative (SFI), a cybersecurity engineering effort launched in November 2023, following a scathing report from the Cyber Safety Review Board of the U.S. Department of Homeland Security that found the company&#8217;s security culture &#8220;inadequate&#8221; and requiring &#8220;an overhaul.&#8221;<\/p>\n<p>&#8220;As part of our Secure Future Initiative (SFI), we will transparently share critical vulnerabilities through the CVE program, even if no customer action is required,&#8221; <a href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/08\/zero-day-quest-join-the-largest-hacking-event-with-up-to-5-million-in-total-bounty-awards\/\" target=\"_blank\" rel=\"nofollow noopener\">Gallagher said<\/a> in August. &#8220;Learnings from the Zero Day Quest will be shared across Microsoft to help improve Cloud and AI security in alignment with SFI&#8217;s core principles: securing by default, by design, and in operations.&#8221;<\/p>\n<p>Earlier that month, Microsoft announced <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-pays-record-17-million-in-bounties-over-the-last-12-months\/\" target=\"_blank\" rel=\"nofollow noopener\">it had paid a record $17 million<\/a> to 344 security researchers across 59 countries through its bug bounty program between July 2024 and June 2025.<\/p>\n<p>In December, it also announced that security researchers would be paid for finding critical vulnerabilities in any of Microsoft&#8217;s online services, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-bounty-program-now-includes-any-flaw-impacting-its-services\/\" target=\"_blank\" rel=\"nofollow noopener\">even if a third party wrote the vulnerable code<\/a>.<\/p>\n<style> .ia_ad {     background-color: #f0f6ff;     width: 95%;     max-width: 800px;     margin: 15px auto;     border-radius: 8px;     border: 1px solid #d6ddee;     display: flex;     align-items: stretch;     padding: 0;     overflow: hidden; }  .ia_lef {     flex: 1;     max-width: 200px;     height: auto;     display: flex;     align-items: stretch; }  .ia_lef a {     display: flex;     width: 100%;     height: 100%; }   .ia_lef a img {     width: 100%;     height: 100%;          border-radius: 8px 0 0 8px;     margin: 0;     display: block; }  .ia_rig {     flex: 2;     padding: 10px;     display: flex;     flex-direction: column;     justify-content: center; }  .ia_rig h2 {     font-size: 17px !important;     font-weight: 700;     color: #333;     line-height: 1.4;     font-family: Georgia, \"Times New Roman\", Times, serif;     margin: 0 0 14px 0; }  .ia_rig p {     font-weight: bold;     font-size: 14px;     margin: 0 0 clamp(6px, 2vw, 14px) 0; }  .ia_button {     background-color: #FFF;     border: 1px solid #3b59aa;     color: black;     text-align: center;     text-decoration: none;     border-radius: 8px;     display: inline-block;     font-size: 16px;     font-weight: bold;     cursor: pointer;     padding: 10px 20px;     width: fit-content; }  .ia_button a {     text-decoration: none;     color: inherit;     display: block; }  @media (max-width: 600px) {     .ia_ad {         flex-direction: column;         align-items: center;     }      .ia_lef {         max-width: 100%;     }      .ia_lef a img {         border-radius: 8px 8px 0 0;     }       .ia_rig {         padding: 15px;         width: 100%;     }      .ia_button {         width: 100%; \tmargin: 0px auto;     } } <\/style>\n<div>\n<div>         <a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">             <img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/p\/picus-whitepaper.jpg\" alt=\"Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest\">         <\/a>     <\/div>\n<div>\n<h2><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">Automated Pentesting Covers Only 1 of 6 Surfaces.<\/a><\/h2>\n<p>Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.<\/p>\n<p>This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.<\/p>\n<p>           <button><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">Get Your Copy Now<\/a><\/button>     <\/div>\n<\/p><\/div>\n<div>\n<h3>Related Articles:<\/h3>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-announces-5-million-prize-pool-for-zero-day-quest-hacking-contest\/\">Microsoft increases Zero Day Quest prize pool to $5 million<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/google\/google-paid-171-million-for-vulnerability-reports-in-2025\/\">Google paid $17.1 million for vulnerability reports in 2025<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days\/\">Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-flags-windows-task-host-vulnerability-as-exploited-in-attacks\/\">CISA flags Windows Task Host vulnerability as exploited in attacks<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-some-windows-servers-ask-for-bitlocker-key-after-april-updates\/\">Microsoft: April updates trigger BitLocker key prompts on some servers<\/a><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has awarded $2.3 million to security research [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"class_list":["post-45446","post","type-post","status-publish","format-standard","hentry","category--bleepingcomputer"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45446"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45446\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}