Tuesday , June 23 2026
365 Bounty

Microsoft to boost M365 bounty program rewards Up to $27,000

Microsoft has announced a major expansion of its Microsoft 365 Bounty Program. The program now covers new Viva products for identifying vulnerabilities, offering rewards up to $27,000 for critical submissions.

This update highlights Microsoft’s commitment to improving software security and promoting global collaboration in finding vulnerabilities.

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

CISA: Splunk flaw under active exploit, patch by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their systems by Sunday from a...
Read More
CISA: Splunk flaw under active exploit, patch by Sunday

Texas data breach exposes 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system provider. This leak exposed private...
Read More
Texas data breach exposes 3 million driver’s licenses

The expanded scope introduces four new Viva products to the program:

Feature Access Control
Glint
Learning
Pulse

These additions are meant to improve the security of the Viva suite, part of Microsoft’s employee experience platform.

Viva works seamlessly with Microsoft Teams and other M365 apps, providing tools for employee engagement, learning, and productivity.

Researchers can now submit vulnerabilities in these components under the categories of “Critical” and “Important,” depending on severity.

Yammer has been rebranded as Viva Engage to unify Microsoft’s Viva product line. Bounty rewards range from $500 to $27,000 USD based on the severity and quality of vulnerability reports.

Critical vulnerabilities in new Viva products qualify for the highest reward. This encourages researchers to tackle important issues that could harm users if ignored. To be eligible for rewards, submissions must meet Microsoft’s strict criteria in their Bounty Terms and Conditions.

Technical Focus Areas:

The M365 Bounty Program encourages researchers to explore certain areas and features of Microsoft 365 services.

The addition of Viva products will likely focus vulnerability assessments on access control, data integrity, and user authentication.

The program’s goal is to identify flaws that could compromise data security or system functionality. For instance:

In Feature Access Control, researchers might examine how permissions are enforced across different user roles.
In Viva Learning, they could analyze integrations with external learning management systems (LMS) or data-sharing protocols.
Pulse and Glint, which focus on employee feedback and analytics, may require scrutiny for potential data leaks or unauthorized access vulnerabilities.
Security researchers interested in participating can visit Microsoft’s official M365 Bounty Program page for detailed guidelines.

Submissions must contain clear proof-of-concept code or steps to reproduce the vulnerability. Reports are assessed for impact, exploitability, and clarity.

Cyber threats are constantly changing, so programs like these are essential for protecting digital environments and enabling ethical hackers to contribute effectively.

Check Also

CISA

ALERT
CISA Warns of Active Attacks on Microsoft SharePoint and Zimbra

Cybersecurity and Infrastructure Security Agency (CISA) have added to its Known Exploited Vulnerabilities (KEV) Catalog. …