Microsoft has launched a new AI bounty program. This program is the result of investments and learnings from recent months, including an AI security research challenge and an update to Microsoft’s vulnerability severity classification for AI systems. Lynn Miyashita, a technical program manager with the Microsoft Security Response Center, shared this information.
The Microsoft AI bug bounty program
By infosecbulletin
/ Wednesday , July 22 2026
Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
By infosecbulletin
/ Wednesday , July 22 2026
Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
By infosecbulletin
/ Wednesday , July 22 2026
The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
By infosecbulletin
/ Saturday , July 18 2026
A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
By infosecbulletin
/ Saturday , July 18 2026
The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
By infosecbulletin
/ Friday , July 17 2026
A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges,...
Read More
By infosecbulletin
/ Thursday , July 16 2026
Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an...
Read More
By infosecbulletin
/ Thursday , July 16 2026
India is speeding up its work to make homegrown AI models for cybersecurity. These models will help protect important digital...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
Microsoft's Patch Tuesday in July 2026 fixes around 570 security flaws in its products. This comes after June's big update,...
Read More
Microsoft wants bug hunters to test AI-powered Bing features on bing.com using a browser. They also want them to test Bing integration on Microsoft Edge, including Bing Chat for Enterprise. Additionally, they want testers to check the Bing integration in the iOS and Android versions of Microsoft Start and Skype mobile apps.
They should report vulnerabilities that could be exploited to:
* Manipulate the model’s response to individual inference requests, but do not modify the model itself (“inference manipulation”)
* Manipulate a model during the training phase (“model manipulation”)
* Infer information about the model’s training data, architecture and weights, or inference-time input data (“inferential information disclosure”)
* Influence/change Bing’s chat behavior in a way that impacts all other users
* Modify Bing’s chat behavior by adjusting client and/or server visible configuration
* Break Bing’s cross-conversation memory protections and history deletion
* Reveal Bing’s internal workings and prompts, decision making processes and confidential information
* Bypass Bing’s chat mode session limits and/or restrictions/rules
Click here to read more