Monday , August 24 2026
365 Bounty

Microsoft to boost M365 bounty program rewards Up to $27,000

Microsoft has announced a major expansion of its Microsoft 365 Bounty Program. The program now covers new Viva products for identifying vulnerabilities, offering rewards up to $27,000 for critical submissions.

This update highlights Microsoft’s commitment to improving software security and promoting global collaboration in finding vulnerabilities.

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

The expanded scope introduces four new Viva products to the program:

Feature Access Control
Glint
Learning
Pulse

These additions are meant to improve the security of the Viva suite, part of Microsoft’s employee experience platform.

Viva works seamlessly with Microsoft Teams and other M365 apps, providing tools for employee engagement, learning, and productivity.

Researchers can now submit vulnerabilities in these components under the categories of “Critical” and “Important,” depending on severity.

Yammer has been rebranded as Viva Engage to unify Microsoft’s Viva product line. Bounty rewards range from $500 to $27,000 USD based on the severity and quality of vulnerability reports.

Critical vulnerabilities in new Viva products qualify for the highest reward. This encourages researchers to tackle important issues that could harm users if ignored. To be eligible for rewards, submissions must meet Microsoft’s strict criteria in their Bounty Terms and Conditions.

Technical Focus Areas:

The M365 Bounty Program encourages researchers to explore certain areas and features of Microsoft 365 services.

The addition of Viva products will likely focus vulnerability assessments on access control, data integrity, and user authentication.

The program’s goal is to identify flaws that could compromise data security or system functionality. For instance:

In Feature Access Control, researchers might examine how permissions are enforced across different user roles.
In Viva Learning, they could analyze integrations with external learning management systems (LMS) or data-sharing protocols.
Pulse and Glint, which focus on employee feedback and analytics, may require scrutiny for potential data leaks or unauthorized access vulnerabilities.
Security researchers interested in participating can visit Microsoft’s official M365 Bounty Program page for detailed guidelines.

Submissions must contain clear proof-of-concept code or steps to reproduce the vulnerability. Reports are assessed for impact, exploitability, and clarity.

Cyber threats are constantly changing, so programs like these are essential for protecting digital environments and enabling ethical hackers to contribute effectively.

Check Also

Anthropic

Anthropic’s Claude Code Source Code Reportedly Leaked

Anthropic’s special Claude Code CLI tool had its complete TypeScript source code inadvertently exposed due …