6 Sources
[1]
Microsoft announces its own Black Hat-like hacking event with big rewards for AI security
Microsoft has announced an open to all research challenge to encourage researchers to discover high-impact vulnerabilities in its programs. Zero Day Quest will offer bug bounties for researchers who report flaws in Microsoft AI, Azure, Identity, Dynamics 365 and Power platform, and M365. The
[2]
Hack Microsoft win $4 million with Zero Day Quest
Microsoft has launched the Zero Day Quest, a new hacking event with a focus on AI and cloud security, offering a total of $4 million in rewards for security researchers. Announced at the Ignite conference in Chicago, this initiative expands Microsoft's bug bounty programs to enhance AI security and
[3]
Microsoft launches Zero Day Quest hacking event with $4 million in rewards
Microsoft announced today at its Ignite annual conference in Chicago, Illinois, that it's expanding its bug bounty programs with Zero Day Quest, a new hacking event focusing on cloud and AI products and platforms. The Zero Day Quest starts today with a research challenge where submissions of
[4]
Microsoft announces its own Black Hat-like hacking event with big rewards for AI security
Microsoft is creating an in-person hacking event, Zero Day Quest, which it says will be the largest of its kind. The event will build upon Microsoft's existing bug bounty program, and incentivize research into high-impact security flaws that can affect the software powering cloud and AI
[5]
Microsoft offers $4 million in AI and cloud bug bounties - how to qualify
The company's Zero Day Quest hacking event will reward researchers who find new security flaws. Hackers and security researchers who uncover vulnerabilities in certain Microsoft products could take home part of a $4 million bug bounty. On Tuesday, the company announced a new invitation-only
[6]
Microsoft Ignite 2024: all the news from Microsoft's IT pro event
Microsoft is creating an in-person hacking event, Zero Day Quest, which it says will be the largest of its kind. The event will build upon Microsoft's existing bug bounty program, and incentivize research into high-impact security flaws that can affect the software powering cloud and AI
Share
Copy Link
Microsoft announces Zero Day Quest, a large-scale hacking event offering $4 million in rewards for uncovering vulnerabilities in AI and cloud technologies, as part of its expanded bug bounty program and Secure Future Initiative.

Microsoft has announced Zero Day Quest, a pioneering hacking event aimed at bolstering security in cloud and AI technologies. This initiative, revealed at the Ignite conference in Chicago, offers a substantial $4 million in potential rewards for researchers who uncover high-impact vulnerabilities
1
2
.Zero Day Quest kicks off with an open research challenge running from November 19, 2024, to January 19, 2025. This phase allows all participants to submit vulnerabilities for specific scenarios, with successful submissions earning multiplied bounty awards
2
. The challenge serves as a qualifier for an exclusive onsite hacking event planned for 2025 at Microsoft's Redmond, Washington campus3
.A key highlight of Zero Day Quest is its emphasis on AI security. Microsoft is doubling bounty awards for AI-related vulnerabilities and providing researchers direct access to its AI engineers and Red Team
2
5
. This move underscores the growing importance of securing AI technologies in an era of rapid advancement.Zero Day Quest expands Microsoft's existing bug bounty programs, covering a wide range of products and platforms including:
1
5
Tom Gallagher, VP of Engineering at the Microsoft Security Response Center (MSRC), emphasized the event's collaborative nature: "Zero Day Quest will provide new opportunities for the security community to work hand in hand with Microsoft engineers and security researchers - bringing together the best minds in security to share, learn, and build community as we work to keep everyone safe"
1
3
.This event is a component of Microsoft's Secure Future Initiative (SFI), launched in November 2023. The SFI represents a significant cybersecurity engineering effort, involving the equivalent of 34,000 full-time engineers focused on high-priority security challenges
2
3
.Related Stories
The launch of Zero Day Quest comes in the wake of several high-profile security incidents involving Microsoft products. These include a Chinese hack of the cloud-based Exchange email platform in May 2023, which resulted in the theft of over 60,000 emails from U.S. State Department accounts
2
3
.To qualify for rewards, researchers must identify previously unreported vulnerabilities that are reproducible and classified as Critical or Important in severity. Successful participants may receive invitations to the 2025 onsite event, with Microsoft covering travel expenses for top-ranked researchers
3
5
.This initiative aligns with Microsoft's efforts to overhaul its security culture, addressing criticisms raised in a report by the Cyber Safety Review Board of the U.S. Department of Homeland Security
3
. By fostering collaboration between external researchers and internal teams, Microsoft aims to enhance its security measures across all products and platforms.Summarized by
Navi
[1]
[2]
[3]
[4]
20 Nov 2024•Technology

10 Dec 2024•Technology

06 Oct 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
