Microsoft today announced that it is expanding its bug bounty program to now include any flaw impacting its services, regardless of whether the code was written by Microsoft or not:
In an AI and cloud-first world, threat actors don’t limit themselves to specific products or services. They don’t care who owns the code they try to exploit. The same approach should apply to the security community who continue to partner with us to provide critical insights that help protect our customers.
Security vulnerabilities often emerge at the seams where components interact or where dependencies are involved. We value research that takes this broader perspective, encompassing not only Microsoft infrastructure but also third-party dependencies, including commercial software and open-source components.
Starting today, if a critical vulnerability has a direct and demonstrable impact to our online services, it’s eligible for a bounty award. Regardless of whether the code is owned and managed by Microsoft, a third-party, or is open source, we will do whatever it takes to remediate the issue. Our goal is to incentivize research on the highest risk areas, especially the areas that threat actors are most likely to exploit. Where no bounty programs exists, we will recognize and award the diverse insights of the security research community wherever their expertise takes them. This includes domains and corporate infrastructure that are owned and managed by Microsoft.
We call this approach In Scope by Default. It gives clarity to researchers and ensures that we incentivize responsible research wherever our customers may be impacted. Historically, our bounty program has had a defined scope for each eligible product or service. Our new approach expands the program to include all online services by default. It also means new services will be in scope as soon as they are released.
Martin Jartelius, AI Product Director at Outpost24 had this to say:
“For organizations that rely on bug bounty programs to keep themselves and their customers secure, this is an important step, as it focuses on the full attack surface of an organization. A very common mistake in security is the careless use of scope, or rather de-scoping, of what is included. As Mr. Gallagher notes, attackers do not care whether they gain access through ReactToShell or a novel vulnerability in Microsoft components. Microsoft will likely find itself paying out more bounties for a while, but the resulting security improvements will ultimately be a cost-efficient way to strengthen the organization’s overall security posture.”
This is a very good move by Microsoft as supply chain attacks are far more pervasive than they should be. Hopefully other vendors do something similar as this will make us all safer.
TELUS partners with AMC-FNFAO and Ka Ni Kanichihk to bring essential connectivity to Indigenous women at risk in Manitoba
Posted in Commentary with tags Telus on December 11, 2025 by itnerdToday, TELUS announced the launch of its Mobility for Good for Indigenous Women at Risk program in Manitoba, in partnership with Assembly of Manitoba Chiefs – First Nations Family Advocate Office (AMC-FNFAO) and Ka Ni Kanichihk, providing wireless services to Indigenous women that may be at risk of or experiencing violence across the province. This partnership against gender-based violence aims to empower First Nations, Métis and Inuit women through access to free phones and wireless plans, helping them stay connected to their support networks, resources and emergency services. While First Nations, Métis and Inuit women and girls comprise only four per cent of the total female population in Canada, they represent 24 per cent of female homicide victims. According to the Native Women’s Association of Canada (NWAC), Manitoba has the third highest number of female homicides in Canada.
Developed in partnership with Indigenous-led organizations, Mobility for Good for Indigenous Women at Risk provides free smartphones and talk, text and data plans to Indigenous women, girls or gender diverse people, serving as a critical lifeline to Indigenous-led services and wellness resources. TELUS is proud to partner with the AMC-FNFAO and Ka Ni Kanichihk to expand this important program to Manitoba, furthering our commitment to serving at-risk Indigenous women and girls.
AMC-FNFAO and Ka Ni Kanichihk have begun distributing smartphones and plans from TELUS to support Indigenous women in Manitoba who are at risk of or surviving violence. Since TELUS launched the program in 2021, more than 6,000 individuals have been supported through 39 partner organizations. This program reflects TELUS’ longstanding commitment to strengthening relationships with Indigenous Peoples, including First Nations, Métis, and Inuit communities, acknowledging that our work spans many Traditional Territories and Treaty areas.
TELUS Mobility for Good for Indigenous Women at Risk is part of the TELUS Connecting for Good portfolio of programs that gives low-income seniors and families, youth aging out of care, and other individuals in need in Canada access to TELUS’ world-leading technology. To date, TELUS’ Connecting for Good and TELUS Wise programs have supported 1.5 million individuals.
For more information on TELUS’ Reconciliation commitment, please visit telus.com/reconciliation.
Leave a comment »