Tech News : Microsoft Pays Bug-Finders $20 Million

Microsoft has paid more than US$20 million to ethical hackers over the past year, its largest bug bounty payout ever, reflecting how the company is increasingly relying on independent security researchers to help identify vulnerabilities before cyber criminals can exploit them.

Bug Bounty Programme Payouts Up

The company’s Microsoft Security Response Center (MSRC) has revealed that its bug bounty programme awarded more than US$20 million to 562 security researchers from 64 countries during the past year, making it the largest payout and the broadest researcher participation in the programme’s history.

The figures represent a substantial increase on the previous year, when Microsoft distributed US$17 million to 344 researchers from 59 countries.

Microsoft says the growth reflects both stronger engagement from the global security research community and important changes it has made to its vulnerability rewards programme.

As the MSRC team explained in an online announcement: “Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers.”

The company added: “The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies.”

Why Are The Rewards Increasing?

One of the biggest reasons is Microsoft’s new “In Scope by Default” policy. For example, previously, researchers were generally rewarded only for vulnerabilities affecting products or services that had been specifically included within Microsoft’s bug bounty programme.

Under the revised approach, announced last year, Microsoft now rewards researchers for finding critical vulnerabilities affecting its online services even when those weaknesses originate in eligible third-party software, open-source projects or external components used by Microsoft.

The policy reflects the reality that modern cloud services increasingly depend on software developed by many different organisations rather than a single vendor.

As Tom Gallagher, Vice President of Engineering at the Microsoft Security Response Center, explained: “If a critical vulnerability has a direct and demonstrable impact on our online services, it’s eligible for a bounty award. Regardless of whether the code is owned and managed by Microsoft, a third-party, or is open source, we will do whatever it takes to remediate the issue.”

Since introducing the expanded programme, Microsoft says it has received more than 300 additional vulnerability reports and paid more than US$800,000 for discoveries that would previously have fallen outside the scope of its rewards programme.

Working With The Research Community

Microsoft has also expanded its Zero Day Quest initiative, bringing together security researchers from 20 countries at its Redmond headquarters to collaborate directly with Microsoft’s engineering and security teams.

The live hacking event focused on Microsoft’s cloud and AI platforms, generating nearly 700 vulnerability reports and awarding researchers a combined US$2.3 million.

Rather than viewing external researchers as outsiders, Microsoft increasingly treats them as an extension of its own security operation.

As the MSRC team said: “This year’s record-breaking results, including more than US$20 million in awards and recognition for 562 researchers, reflect the impact of a strong partnership between Microsoft and the global security research community.”

It added: “Researchers continue to play a vital role in protecting customers around the world.”

Individual rewards can also be substantial. Depending on the vulnerability involved, Microsoft’s programmes now pay up to US$100,000 for many cloud vulnerabilities and as much as US$250,000 for qualifying endpoint and on-premises security issues.

Why AI Is Changing Bug Hunting

The announcement also reflects a wider change taking place across cyber security. Artificial intelligence is helping many security researchers analyse software more quickly, automate repetitive testing and identify potential weaknesses that previously required much more manual investigation.

Microsoft says it experienced a notable increase in vulnerability submissions during the second half of the year, reflecting both growing participation from researchers and the increasing use of AI to support security research.

At the same time, AI is creating new challenges. For example, security teams across the industry have reported growing numbers of low-quality vulnerability reports generated largely by AI tools, requiring significant effort to assess before determining whether a genuine security issue exists.

Microsoft’s expanded programme therefore reflects not only greater investment in security research but also the increasing need to distinguish valuable discoveries from automated noise.

Security Through Collaboration

Perhaps the most significant aspect of Microsoft’s announcement is what it says about how cyber security itself is changing.

Rather than relying solely on internal testing, organisations are increasingly recognising that thousands of independent researchers examining software from different perspectives can identify vulnerabilities that internal teams may never encounter.

Microsoft’s decision to reward research involving third-party code also acknowledges that modern technology ecosystems are highly interconnected. A vulnerability affecting an open-source component may ultimately present just as much risk to Microsoft customers as one discovered within Microsoft’s own software.

The company’s approach therefore broadens responsibility for security while encouraging researchers to investigate the areas most likely to matter to customers.

What Does This Mean For Your Business?

For businesses, Microsoft’s record investment should provide reassurance that the company is continuing to strengthen the security of the products and cloud services on which many organisations depend every day. Finding vulnerabilities before attackers do remains one of the most effective ways of reducing cyber risk, and Microsoft’s willingness to reward responsible disclosure demonstrates how seriously it now views collaborative security research.

The announcement also highlights an important change in how software security is managed. Modern applications increasingly rely on open-source software, cloud infrastructure and third-party components, meaning vulnerabilities can emerge well beyond the boundaries of a single vendor’s own code. Businesses should therefore expect software suppliers to take greater responsibility for securing their wider technology ecosystems rather than focusing solely on their own products.

Microsoft’s latest figures, therefore, seem to show that cyber security is becoming an increasingly collaborative discipline. As AI accelerates both software development and vulnerability discovery, partnerships between technology companies and independent researchers are likely to become even more important in identifying weaknesses before malicious attackers have the opportunity to exploit them.

Company Check : Windows 11 Slims Down

Microsoft is redesigning parts of Windows 11 to use less memory, a move that could help millions of older and lower-cost PCs remain responsive as rising RAM prices make hardware upgrades increasingly expensive.

Why Is Microsoft Doing This?

The company has confirmed that reducing Windows’ memory footprint has become one of its major engineering priorities.

Writing in an update on Microsoft’s Windows quality programme, Pavan Davuluri, President of Windows and Devices, said the company is focusing on “memory optimisation for 8GB and above” by “reducing Windows memory footprint to deliver a fast and responsive Windows experience across the PCs customers use every day.”

The announcement forms part of a broader initiative to improve Windows 11 performance, reliability and responsiveness while making everyday tasks feel faster and smoother.

Although Microsoft has not linked the changes directly to the global memory shortage, the timing is significant. Memory prices have risen sharply as AI infrastructure consumes increasing quantities of advanced memory chips, making even budget PCs more expensive to manufacture.

That matters because many Windows computers still operate with 8GB of RAM, particularly lower-cost laptops purchased by home users, schools and small businesses.

How Will Windows Use Less Memory?

Rather than removing features, Microsoft says it’s redesigning how Windows manages memory behind the scenes.

One area receiving attention appears to be the operating system’s memory allocator, which determines how Windows distributes RAM between applications and system components. Improving that process reduces unnecessary overhead and leaves more working memory available for users’ software.

Microsoft says it’s also continuing to optimise WinUI 3, the framework behind many modern Windows applications.

As Davuluri explained, Microsoft has delivered “substantial improvements in memory efficiency and latency”, adding that “these investments are strengthening the platform foundation needed to accelerate the modernisation of Windows 11 and the broader application ecosystem.”

The company is also improving Chromium and WebView2, technologies that underpin Microsoft Edge and many Windows applications. Since these components appear throughout Windows, even relatively small efficiency improvements can reduce memory consumption across the operating system.

Taken together, the changes are intended to make Windows feel more responsive without requiring additional hardware.

Can Software Really Replace More RAM?

In reality, the short answer is yes, but only up to a point. Microsoft isn’t suggesting that software optimisation can turn an 8GB computer into the equivalent of a 16GB machine. Applications still require physical memory, and demanding workloads such as video editing, software development, engineering design and advanced AI tools will continue to benefit significantly from larger amounts of RAM.

However, operating systems themselves inevitably consume part of the available memory before users even open an application.

Reducing that overhead means more RAM remains available for web browsers, office applications, video conferencing software and other everyday workloads. On lower-specification devices, even relatively modest reductions in memory usage can improve responsiveness by reducing the need for Windows to move data between RAM and slower storage.

The result is not necessarily a more powerful PC, but one that feels faster during everyday use.

The AI Hardware Challenge

The announcement also reflects a wider challenge facing today’s PC industry.

Over the past year, Microsoft has invested heavily in Copilot+ PCs, a new category of AI-capable computers that require a neural processing unit delivering at least 40 trillion operations per second, together with a minimum of 16GB of RAM.

Those specifications enable advanced AI features to run directly on the device rather than relying entirely on cloud computing. However, they also place many lower-cost computers outside the Copilot+ ecosystem.

At the same time, rising memory prices have increased the cost of building mainstream PCs, making 16GB configurations less affordable than many manufacturers had expected.

Optimising Windows for 8GB devices therefore allows Microsoft to improve the experience for millions of existing users while the wider hardware market adjusts to changing component costs.

Rather than encouraging immediate replacement, Microsoft appears to be extending the useful life of existing computers that remain perfectly capable of handling everyday business tasks.

Part Of A Wider Windows Refresh

It should be noted here, however, that memory optimisation is really only one element of Microsoft’s broader Windows quality programme.

The company says it has already introduced improvements across File Explorer, Windows Search, Start, the taskbar, Windows Hello, printer support, Bluetooth connectivity and Windows Update while continuing to strengthen the underlying architecture of Windows 11.

Davuluri said: “We’re continuing to invest across the full stack, from the kernel and shell to the apps and developer tools built on Windows, so performance improvements benefit the broad range of ways people use Windows.”

He added that “application launches and experiences like Start, File Explorer, Search, and Snipping Tool are faster and more responsive”, while boot and logon times have also improved.

Many of these enhancements have already appeared in Windows Insider preview builds and are expected to roll out more widely through future Windows 11 updates.

What Does This Mean For Your Business?

For businesses, Microsoft’s announcement offers some reassurance that existing Windows hardware may remain productive for longer than many organisations had anticipated. Improving memory efficiency can’t overcome genuine hardware limitations, although it can help extend the useful life of devices that still perform well for everyday office applications, helping businesses delay costly replacement programmes during a period of unusually high component prices.

The announcement also highlights an important change in how software companies are responding to AI-driven hardware costs. For example, rather than relying solely on increasingly powerful specifications, Microsoft is investing in making Windows itself more efficient so that performance improvements benefit a much wider range of devices. That approach could prove particularly valuable while global memory supplies remain constrained and hardware costs continue to fluctuate.

A key point to note here is that Microsoft’s latest work demonstrates that software optimisation still has an important role alongside advances in hardware. Faster processors and larger amounts of memory will always improve performance, although making better use of the resources that computers already have can often deliver meaningful gains without requiring users to buy entirely new machines.

Video Update : New Central Prompt Library Now In Copilot

Microsoft Copilot’s new Central Prompt Library gives you a single place to browse, save and reuse effective AI prompts, making it quicker and easier to get consistent, high-quality results without having to recreate prompts from scratch every time.

[Note – To watch this video without glitches/interruptions, it may be best to download it first]

Tech Tip : Quickly Find Every Photo On Your PC

Finding an image you saved weeks or even years ago can be frustrating if you can’t remember which folder it’s in. Fortunately, Windows includes a simple search feature that can locate every picture within a folder and all its subfolders in seconds.

How It Works

Instead of searching by filename, File Explorer can search by file type. By using the search term kind:=picture, Windows looks for recognised image formats, including JPG, PNG, GIF, BMP and others, regardless of what the files are called.

This makes it an easy way to find screenshots, downloaded images, scanned documents or photographs without manually browsing through folders.

How To Find All Your Photos

  1. Open ‘File Explorer’.
  2. Browse to the drive or folder you want to search.
  3. Click in the ‘Search’ box in the top-right corner.
  4. Type ‘kind:=picture’ and press ‘Enter’.
  5. Windows will display every recognised image in that location and its subfolders.

One Thing To Be Aware Of

The search only looks within the folder you currently have open. If you’re unsure where an image is stored, start your search from ‘This PC’ or your main ‘Pictures’ folder to search a much wider area.

Tech Insight : Microsoft Makes Passkeys The Default For Entra ID

Microsoft will begin making passkeys the default authentication method in Microsoft Entra ID from 1 September 2026, marking a major change in how organisations protect user accounts as AI-powered phishing and identity attacks continue to grow.

What Has Changed?

The move is part of Microsoft’s wider effort to reduce reliance on authentication methods that cyber criminals can intercept, steal or manipulate, such as SMS text messages and voice calls.

From 1 September 2026, organisations using Microsoft Entra ID will see users who currently rely on SMS or voice authentication automatically enabled for passkeys. The next time those users complete multifactor authentication, they will be prompted to register a passkey.

Microsoft says: “As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey.”

The company is also encouraging organisations to begin preparing now rather than waiting for the rollout to begin.

Why Microsoft Is Making The Move

Microsoft says the decision reflects the changing nature of cyber attacks, particularly as AI enables criminals to launch more sophisticated phishing campaigns at greater speed and scale.

In announcing the change, the company said: “As identity attacks grow more sophisticated in the AI era, organisations need stronger authentication methods that protect users from phishing, credential theft, and social engineering.”

Traditional multifactor authentication using SMS or voice was once considered a major improvement over passwords alone. However, Microsoft says these methods still rely on shared secrets or communication channels that attackers increasingly know how to exploit.

The company points to techniques such as SIM swapping, social engineering and multifactor authentication bypass attacks, all of which have become more accessible to attackers.

Microsoft also says AI is making the problem significantly worse. For example, according to Microsoft Threat Intelligence, AI-enabled phishing campaigns have achieved click-through rates of up to 54 per cent, compared with roughly 12 per cent for more traditional phishing attacks.

The company warns that once an attacker compromises an identity, AI can rapidly automate discovery, privilege escalation and lateral movement across an organisation, dramatically increasing the speed and scale of an attack.

Why Passkeys Are Different

Unlike passwords or SMS authentication codes, passkeys use public-key cryptography rather than shared secrets. That means there is no password or authentication code that can be intercepted, stolen or tricked out of a user through a phishing website.

Microsoft says this makes passkeys phishing-resistant by design while also simplifying the sign-in process.

As the company explains: “Passkeys use public-key cryptography rather than shared secrets, making them phishing-resistant by design. They also provide a faster, simpler sign-in experience for users.”

Microsoft Entra ID supports a range of passkey options, including synchronised passkeys stored in services such as iCloud Keychain and Google Password Manager, device-bound passkeys stored in Microsoft Authenticator or Windows, and FIDO2 hardware security keys.

What Happens Next?

The introduction of passkeys is only the first stage of Microsoft’s transition.

On 1 February 2027, Microsoft says it will retire its own SMS and voice authentication capability within Entra ID altogether. Organisations that still require those authentication methods because of regulatory, operational or technical requirements will instead need to obtain them through third-party telecoms providers available via the Microsoft Security Store.

Microsoft says organisations should begin identifying users who still rely on SMS or voice authentication, plan their passkey deployment strategy, communicate upcoming changes to staff and use Entra ID’s built-in registration campaigns to encourage adoption before the deadlines arrive.

Summarising the transition, Microsoft said: “SMS and voice have served their purpose well, bringing multifactor authentication to billions of users who otherwise would have had none. But the threat environment has evolved beyond their capabilities, and we need to evolve with it.”

What Does This Mean For Your Business?

For businesses, Microsoft’s announcement reflects a much broader change in cyber security. As AI makes phishing attacks more convincing and easier to automate, organisations are increasingly moving away from authentication methods that depend on passwords, text messages and one-time codes.

The change also shows that passkeys are rapidly becoming the new standard for business identity protection rather than an emerging technology. Organisations that continue relying heavily on SMS or voice authentication may find themselves under increasing pressure to modernise as software suppliers, regulators and cyber insurers place greater emphasis on phishing-resistant authentication.

The move reflects a wider change across the cyber security industry as organisations look to replace authentication methods that can be phished, intercepted or manipulated with stronger, phishing-resistant alternatives.

For businesses already using Microsoft Entra ID, the message is that now is the time to begin planning the move to passkeys, preparing users for the change and ensuring authentication policies are ready well before Microsoft’s new deadlines take effect.

Tech Tip : Instantly Find Microsoft Office Commands

If you can’t remember where a command is in Word, Excel or PowerPoint, Microsoft Office includes a built-in Search feature that can take you straight to it in seconds, saving you from hunting through menus and Ribbon tabs.

This can be particularly useful when using features you don’t access very often, such as Track Changes, Mail Merge, Page Breaks or PivotTables.

How To Find Any Command Quickly

In Word, Excel or PowerPoint:

  • Click the Search box at the top of the window, or press Alt + Q.
  • Type the name of the command or feature you’re looking for.
  • Select it from the list of results.

Office will either take you directly to the command or carry out the action immediately, depending on what you’ve selected.

Why This Is Useful

The Microsoft Office Ribbon contains hundreds of commands spread across multiple tabs, making it easy to forget where less frequently used features are located.

Using the Search box is often much quicker than browsing through menus and can also help you discover features you didn’t know were available.

Video Update : Copilot ‘Cowork’ – You Just Describe Outcome

Microsoft’s new ‘Cowork’ feature in Copilot lets you assign tasks by simply describing the outcome, with Copilot creating a plan, using your Microsoft 365 data, and carrying out tasks across apps in the background while keeping you in control at every step.

[Note – To Watch This Video without glitches/interruptions, It may be best to download it first]

Tech Tip : Check If Windows Backup Is Saving Your Settings

Microsoft is making Windows Backup automatically switch on for many Windows 11 devices, so it’s worth checking what is being backed up and deciding whether you’re happy with the setting.

What Windows Backup Does

Windows Backup, now called Windows settings backup and restore, saves your Windows settings and a list of your Microsoft Store apps to your Microsoft account. If you replace or reset your PC, those settings can be restored to help you get up and running more quickly.

It does not create a full backup of your files, programs or entire computer.

How To Check Or Change The Setting

On a personal Windows 11 PC:

  • Open ‘Settings’.
  • Select ‘Accounts’.
  • Choose ‘Windows backup’.
  • Review which options are switched on, such as preferences and app settings.
  • Turn the options on or off as required.

You can also open the ‘Windows Backup’ app to see your current backup status and start a backup manually if you wish.

One Thing To Be Aware Of

If your work PC is managed by your organisation, these settings may be controlled by your IT department and you may not be able to change them yourself. Also, remember that Windows Backup is designed to preserve settings and app information, not replace a proper backup of your important files, so it should still be used alongside your normal backup strategy.

Company Check : Italy Probes Microsoft 365 AI Price Rise

Italy’s competition authority has opened an investigation into Microsoft over the way it introduced a higher-priced Microsoft 365 subscription that includes its AI tools Copilot and Designer, raising wider questions about how software companies should bundle artificial intelligence into products that millions of people already use.

What’s Happened?

The Italian Competition Authority (Autorità Garante della Concorrenza e del Mercato, or AGCM) announced on 26 June that it had launched an investigation into Microsoft Ireland Operations Ltd. and Microsoft S.r.l.

It’s important to stress here that opening an investigation doesn’t mean Microsoft has done anything wrong. Rather, it allows the regulator to examine whether consumers received sufficient information before being moved to a more expensive Microsoft 365 subscription that includes Copilot and Designer. The price increase is due to take effect from 1 July 2026.

Why Is Italy Investigating?

The regulator’s concerns focus less on the price increase itself and more on how it was introduced.

According to the AGCM, Microsoft “appears to have failed to make it sufficiently clear that the subscription service had been integrated with the ‘Copilot’ and ‘Designer’ artificial intelligence services.”

The authority also alleges that customers were placed, by default, on a higher-priced subscription unless they actively exercised their right to withdraw, while receiving insufficient information to decide whether to renew their subscription.

In the regulator’s view, this may have prevented consumers from making a fully informed decision about whether they wanted the additional AI features or the higher-priced plan.

The AGCM also stated that the way the changes were communicated “may also constitute an aggressive practice, as it appears to have unduly restricted consumers’ freedom of choice.”

Default Choices

Although the investigation concerns Microsoft 365, it reflects a much broader issue that regulators are increasingly examining.

For example, many digital services now present customers with default choices that require them to actively opt out rather than opt in. In practice, a significant proportion of users simply accept the default option, either because they overlook the change or assume it is mandatory.

The Italian authority therefore appears to be examining whether consumers were actually given a genuine opportunity to understand the changes before being automatically moved onto a more expensive subscription.

The investigation is not questioning Microsoft’s right to charge more for software that includes new capabilities. Instead, it is asking whether customers were given enough information to make an informed decision about whether those additional AI features justified the extra cost.

Microsoft’s Response

Microsoft says it intends to cooperate fully with the investigation. In a statement, the company said: “Microsoft is committed to complying with Italian consumer law and will cooperate with the Italian Competition Authority in its preliminary investigation.”

The company will now have an opportunity to present its own evidence and arguments before the authority reaches any conclusions.

At this stage, there is no finding of wrongdoing and no indication of what the eventual outcome might be.

Part Of A Bigger AI Debate

The case also illustrates how AI is beginning to reshape long-established software business models. For example, rather than selling AI as an entirely separate product, many software providers are now integrating AI features directly into existing subscriptions. Microsoft has already embedded Copilot across much of its software portfolio, while other technology companies are following similar strategies.

That approach can make advanced AI capabilities available to many more users. However, it also raises questions about pricing, transparency, and whether customers who have little interest in AI should automatically pay for features they may never use.

As AI becomes more deeply integrated into mainstream software, regulators are likely to pay increasing attention to how those changes are communicated and whether consumers are given meaningful choices.

What Does This Mean For Your Business?

For organisations, the investigation highlights the importance of paying close attention whenever software vendors change subscription terms or introduce new product bundles.

AI is increasingly being incorporated into familiar business applications rather than being offered as a standalone service. While those new capabilities may bring genuine benefits, they can also alter pricing structures, licensing arrangements and the features included within existing subscriptions.

The wider lesson here is that software procurement is becoming more complex as AI becomes a standard component of mainstream business software. Organisations should ensure they understand exactly what has changed, whether additional AI features meet their operational needs, and what options exist before renewing subscription agreements.

Whatever the outcome of the Italian investigation, it is likely to influence how software companies introduce AI into existing products in the future. The issue is no longer simply whether organisations are willing to pay more for artificial intelligence, but whether customers are given clear information and genuine choice before those additional costs become part of the software they already depend upon.