Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
UK Government Cyber-Attacks Target 23 Million Users, Forcing Password Phase-Out
September 14, 2026
Critical Vite Vulnerability Exposes AWS, Azure Credentials
September 14, 2026
Microsoft Bug Bounty Offers $30K for Critical Dynamics 365, Power Platform AI Flaws
September 14, 2026
Home/CyberSecurity News/Microsoft Bug Bounty Offers $30K for Critical Dynamics 365, Power Platform AI Flaws
CyberSecurity News

Microsoft Bug Bounty Offers $30K for Critical Dynamics 365, Power Platform AI Flaws

Key Takeaways Microsoft has expanded its bug bounty program to specifically target critical AI vulnerabilities within its Dynamics 365 and Power Platform ecosystems. Researchers can earn up to...

Sarah simpson
Sarah simpson
September 14, 2026 4 Min Read
2 0

Key Takeaways

  • Microsoft has expanded its bug bounty program to specifically target critical AI vulnerabilities within its Dynamics 365 and Power Platform ecosystems.
  • Researchers can earn up to $30,000 for uncovering flaws related to AI inference manipulation or inferential information disclosure.
  • The program covers a wide array of Microsoft-hosted services and embedded third-party components, emphasizing high-impact security implications.
  • Beyond AI, significant bounties are also offered for critical Remote Code Execution (RCE) and cross-tenant information disclosure.

Microsoft Boosts Bug Bounty for Critical AI Flaws in Dynamics 365, Power Platform

Microsoft has significantly augmented its bug bounty program, now offering up to $30,000 to cybersecurity researchers who identify critical artificial intelligence vulnerabilities within its Dynamics 365 and Power Platform suites. This strategic move underscores Microsoft’s sharpened focus on mitigating risks associated with AI models, particularly those that could lead to inference manipulation or unauthorized information exposure through model behavior.

Table Of Content

  • Key Takeaways
  • Microsoft Boosts Bug Bounty for Critical AI Flaws in Dynamics 365, Power Platform
  • Payout Structure for AI Vulnerabilities
  • Broad Scope Reflects Platform Importance
  • Reporting Requirements and Exclusions
  • What You Should Do

The updated program encompasses eligible bugs found in Microsoft-hosted services, as well as any third-party or open-source components integrated within these platforms. To qualify for a reward, researchers must conclusively demonstrate a tangible security impact on an in-scope service.

Payout Structure for AI Vulnerabilities

Under the revised bounty framework, the highest reward of $30,000 is reserved for top-tier reports detailing critical “Inference Manipulation” or “Inferential Information Disclosure” vulnerabilities. Should the quality of the report for a critical impact be rated as medium or low, payouts are adjusted to $20,000 and $12,000, respectively. For important-severity findings, researchers can expect between $6,000 and $20,000, depending on the report’s quality. It is important to note that AI submissions categorized as moderate or low severity do not qualify for monetary rewards under this specific bounty category.

Vulnerability Category / Focus Area Impact Severity & Quality Tier Maximum Payout / Multiplier Scope & Qualification Details
Inference Manipulation & Disclosure Critical (High / Med / Low Quality) $30,000 / $20,000 / $12,000 Manipulates model responses or extracts data via model behavior
Important AI Vulnerabilities Important (High / Med / Low Quality) $20,000 / $12,000 / $6,000 High-impact functional or security flaws across AI integrations
Remote Code Execution (RCE) Critical Severity Up to $20,000 Code execution flaws across in-scope cloud and service components
Cross-Tenant Information Disclosure High-Impact Scenario Up to $20,000 Breaches tenant boundaries to access external organization data
Elevation of Privilege / Info Disclosure Critical Severity Up to $12,000 Local and cloud-level unauthorized privilege escalation
Dataverse & Sandbox Escapes Special High-Impact Vectors +20% Multiplier Dataverse privilege escalation & Plugin Sandbox host escapes

Broad Scope Reflects Platform Importance

The extensive scope of the program highlights the critical role these platforms play in handling sensitive business data and automating complex workflows. Eligible targets span a comprehensive list of Dynamics 365 products, including Sales, Customer Service, Finance, Commerce, Human Resources, Business Central, Contact Center, Customer Insights, and Supply Chain Management, alongside their on-premises counterparts. The Power Platform components covered include Power Apps, Power Automate, Copilot Studio, Power Pages, Power Admin, AI Builder, and Dataverse.

For AI findings to be considered, they must meet Microsoft’s definitions for Critical or Important severity and be reproducible on the latest, fully patched versions of the specified products.

Reporting Requirements and Exclusions

Researchers are required to submit their findings via the MSRC Researcher Portal. Submissions must include the Power Platform or Dynamics environment ID, the username utilized during testing, and an indication of whether the bug aligns with a high-impact scenario. Providing clear reproduction steps, proof-of-concept materials, details of affected versions, and an explanation of the potential attacker impact can significantly expedite the validation process and support a higher reward.

Beyond AI-specific payouts, the broader bug bounty program offers up to $20,000 for critical remote code execution flaws, $12,000 for critical elevation-of-privilege or information-disclosure vulnerabilities, and $8,000 for critical spoofing or tampering reports. Cross-tenant information disclosure scenarios can yield a $20,000 high-impact award. Furthermore, qualifying Dataverse privilege escalation and Plugin Sandbox “guest-to-host” escapes are eligible for a 20% multiplier on top of their base reward. While a report may qualify for multiple awards, only the highest applicable payment will be granted, though Microsoft reserves the right to offer additional compensation at its discretion.

Microsoft explicitly distinguishes exploitable AI security failures from mere model quirks. Out-of-scope issues include prompt injection affecting only the attacker, hallucinated code execution, attempts solely to reveal system or meta prompts, and content-safety concerns. Similarly, publicly known bugs, denial-of-service attacks, blind cross-site scripting, dependency confusion, and configuration-dependent weaknesses are generally excluded from the program.

What You Should Do

  • Researchers must conduct testing exclusively within accounts and tenants they own or are explicitly authorized to assess.
  • Immediately cease testing if unauthorized data becomes accessible.
  • Refrain from engaging in post-exploitation activities, lateral movement, phishing, or any disruptive network traffic.
  • Microsoft recommends marking research tenants with “MSOBB” where feasible.
  • Adhere to coordinated vulnerability disclosure practices to ensure findings reach engineers responsibly without jeopardizing customers or production services.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitPatchphishingSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Nintendo Switch Bug Lets Attackers Run Unauthorized Code

Next Post

Critical Vite Vulnerability Exposes AWS, Azure Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks
September 14, 2026
WhatsApp’s Restricted Chat Feature Improves Privacy and Security
September 14, 2026
Critical Sogou Input Method RCE Vulnerability Lets Attackers Backdoor Users
September 14, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us