Monday , September 14 2026
365 Bounty

Microsoft to boost M365 bounty program rewards Up to $27,000

Microsoft has announced a major expansion of its Microsoft 365 Bounty Program. The program now covers new Viva products for identifying vulnerabilities, offering rewards up to $27,000 for critical submissions.

This update highlights Microsoft’s commitment to improving software security and promoting global collaboration in finding vulnerabilities.

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

The expanded scope introduces four new Viva products to the program:

Feature Access Control
Glint
Learning
Pulse

These additions are meant to improve the security of the Viva suite, part of Microsoft’s employee experience platform.

Viva works seamlessly with Microsoft Teams and other M365 apps, providing tools for employee engagement, learning, and productivity.

Researchers can now submit vulnerabilities in these components under the categories of “Critical” and “Important,” depending on severity.

Yammer has been rebranded as Viva Engage to unify Microsoft’s Viva product line. Bounty rewards range from $500 to $27,000 USD based on the severity and quality of vulnerability reports.

Critical vulnerabilities in new Viva products qualify for the highest reward. This encourages researchers to tackle important issues that could harm users if ignored. To be eligible for rewards, submissions must meet Microsoft’s strict criteria in their Bounty Terms and Conditions.

Technical Focus Areas:

The M365 Bounty Program encourages researchers to explore certain areas and features of Microsoft 365 services.

The addition of Viva products will likely focus vulnerability assessments on access control, data integrity, and user authentication.

The program’s goal is to identify flaws that could compromise data security or system functionality. For instance:

In Feature Access Control, researchers might examine how permissions are enforced across different user roles.
In Viva Learning, they could analyze integrations with external learning management systems (LMS) or data-sharing protocols.
Pulse and Glint, which focus on employee feedback and analytics, may require scrutiny for potential data leaks or unauthorized access vulnerabilities.
Security researchers interested in participating can visit Microsoft’s official M365 Bounty Program page for detailed guidelines.

Submissions must contain clear proof-of-concept code or steps to reproduce the vulnerability. Reports are assessed for impact, exploitability, and clarity.

Cyber threats are constantly changing, so programs like these are essential for protecting digital environments and enabling ethical hackers to contribute effectively.

Check Also

Anthropic

Anthropic’s Claude Code Source Code Reportedly Leaked

Anthropic’s special Claude Code CLI tool had its complete TypeScript source code inadvertently exposed due …