Microsoft Expands Bug Bounty with 'In Scope by Default'
🛡️ Microsoft unveiled a new security policy, In Scope by Default, at Black Hat Europe to expand its bug-bounty coverage to any critical vulnerabilities that demonstrably affect its online services. The program covers Microsoft-managed code as well as third-party and open source components when no existing bounty exists. Researchers submit reports via Microsoft’s coordinated disclosure platform under defined rules that permit broad red-team testing while prohibiting credential access, phishing, and excessive DoS.
