Microsoft is so concerned about security in its Copilot products for folks that it’s lifted bug bounty payments for moderate-severity vulnerabilities from nothing to a maximum of $5,000, and expanded the range of vulnerabilities it will pay people to find and report. The payouts for less severe vulns were introduced because the software giant thinks "even moderate vulnerabilities can have significant implications for the security and reliability of our Copilot consumer products," explained Microsoft bounty team members Lynn Miyashita and Madeline Eckert earlier this month. Under the Copilot Bounty Program, researchers who identify and disclose previously unknown vulnerabilities can earn between $250 and $30,000. As is typical in bug bounty programs, higher payouts are reserved for those who report the most serious vulnerabilities, such as code injection or model manipulation. Microsoft classifies security flaws into four severity levels - Critical, Important, Moderate, and Low - based on the Microsoft Vulnerability Severity Classification for AI Systems and the Microsoft Vulnerability Severity Classification for Online Services. Redmond also recently expanded the Copilot (AI) Bounty Program to cover 14 types of vulnerability, up from three, an understandable decision given its push to embed the generative AI assistants across its product portfolio. The three old-school vulns are inference manipulation, model manipulation and inferential information disclosure. The new vuln ty...
Microsoft expands Copilot bug bounty targets, payouts
The Register
·Jessica Lyons
·Published Feb 20, 2025
·Updated
Affected Software
3 affected components
Microsoft Copilot
Microsoft Bing AI
Microsoft Copilot
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft increasing bug bounty payments and expanding the scope for its Copilot products.
2
What security implications are discussed in the article?
The article highlights Microsoft's commitment to addressing vulnerabilities in its Copilot products and the potential impact of these vulnerabilities on users.
3
What products or software are affected by the updated bug bounty program?
The affected products include Microsoft Copilot and Microsoft Bing AI.
4
What changes were made to the bug bounty payouts?
Moderate-severity vulnerabilities now have a maximum payout of $5,000, up from nothing.
5
Why is Microsoft expanding its bug bounty program?
Microsoft is expanding its bug bounty program to enhance security and encourage the discovery of vulnerabilities in its Copilot offerings.