July 21, 2026
How I Earned $10,000 From Microsoft (From Just 2 Bugs Out of 30+)
One year. More than thirty reports to Microsoft, only two of them paid, and a whole security conference built on the side while I did it…

By Aman Kumar (ak)
12 min read
One year. More than thirty reports to Microsoft, only two of them paid, and a whole security conference built on the side while I did it. Those two bugs still paid $10,000, and one of them doubled because I refused to take the first answer. This is the full and honest version, wins and dead ends both.
Hello everyone, Aman Kumar (ak) here.
$10,000. That is what Microsoft paid me over a year of hunting their systems.
Sounds like a flex, right? Like one of those posts where somebody throws up a payout screenshot and says "anyone can do this, just grind bro."
Nope. Because here is the number that kind of post always leaves out. In that same year, I reported more than 30 bugs to Microsoft. Only two of them paid me anything. Two. The rest were duplicates, out of scope, acknowledged with zero dollars, or just not good enough.
So consider this the honest version. The full ledger, top to bottom.
I already wrote deep technical breakdowns of both these bugs on this blog. Those posts tear apart the how, the payloads, the exact steps. This one is different. This is the story behind the money. What it took, what it felt like, and what a full year on Microsoft's attack surface taught one independent hunter with a laptop in Dehradun.
And one thread runs through this whole story, so I will say it up front. For most of that year I was not only hunting. I was also building a security conference, Security BSides Dehradun, our 0x02 edition. It shaped everything you are about to read, including why this list of bugs is not longer.
Let me break it all down.
The Honest Numbers, Before the Highlight Reel
Everyone shows you the highlight reel. Let me show you the whole tape first.
Over the last year I did not report 2 bugs to Microsoft. I reported more than 30. Across Azure, Copilot, Xbox, Gaming, .NET, Dynamics, and Bing. Different products, different bug classes, and a lot of very quiet, very boring grinding.
Now, some people look at that and ask: thirty in a year, that is it? Fair question, so here is the honest answer. From July to December, exactly the stretch I was deepest into hunting, I was also running BSides Dehradun 0x02. Organizing the whole conference. Learning to manage a team of around 25 people for the first time in my life, leaning hard on everything our first two editions had taught me. Building an event out of nothing, while trying to break into Microsoft in whatever hours were left over.
So no, thirty is not a giant number. But every one of those reports got written between sponsor emails, speaker calls, and volunteer chaos. Honestly? I am prouder of thirty under that load than I would be of a hundred with nothing else going on.
Here is how those thirty-odd reports actually shook out:
- 2 paid. That is it. Two.
- Around 5 got selected for bounty review, and then ruled out of scope.
- A whole stack got confirmed, fixed, and publicly acknowledged, with zero dollars attached.
- A handful came back "not applicable." Duplicate, by design, or just plain wrong.
- 1 is still open right now, and I cannot talk about it yet. More on that at the end.
Now here are the two numbers that actually taught me something.
I filed around a dozen information disclosure bugs. Exactly one of them paid.
I filed around seven RCE-class bugs. The scary kind, remote code execution. Again, one of them paid.
And here is the stat that still makes me laugh. I threw eleven reports at Azure alone. Azure. The crown jewel. Not one of them paid a single rupee. Both of my paydays came from the two places I almost did not bother looking at hard: a Copilot staging server, and a Bing Ads pipeline.
The two that actually paid:
- An LFI on a Microsoft Copilot staging server. $5,000.
- A Dependency Confusion bug on the Bing Ads build pipeline. $5,000 (and yes, there is a whole story hiding inside that one).
Total: $10,000.
That work also put me on the MSRC Researcher Leaderboard for Q3 and Q4 2025, and then on the MSRC Special Mentions list for the Jul '25 to Jun '26 cycle.
Those two lines mean more to me than the money ever did. Money gets spent. Recognition from a team that reads thousands of reports a year does not wash off.
Okay. Now the highlight reel.
The $5,000 Bug That Was Almost Embarrassingly Simple
This first one taught me something I now repeat to every beginner who asks me for advice. The bug is never in the place everyone is looking.
I was poking around a Microsoft Copilot staging subdomain. (I am masking the full name here, because Microsoft asked me to, and keeping my word to them matters more to me than a cool screenshot.) This staging box was running a frontend development server.
Now stop and sit with that for a second. A development server. On the public internet. On a Microsoft domain.
Development servers are built for exactly one thing, and that is speed for the developer. They are meant to run on your own laptop, on localhost, behind a locked door. They trust everything, because they assume only you are talking to them. When one of them ends up facing the whole internet, it is like leaving the back door of a bank propped open because you only ever expected staff to walk through it.
This one had a path traversal flaw, from the same family as CVE-2025–30208. Picture it like a hotel front desk. You ask for the file for Room 101. Fine, that is your room. But then you ask for the file "two floors down and three doors to the left," and the clerk just… hands it to you. That is path traversal. You ask for a path outside where you are allowed to be, and the server happily walks over, grabs it, and brings it back.
So I asked the server for /etc/passwd, the classic "prove you actually have file access" target on any Linux box.
Boom. It handed it over.
That was the whole thing. No exploit chain, no custom tooling. Just a dev server sitting somewhere it never should have been, reading out system files to anyone who asked nicely. Microsoft confirmed it, patched it fast, acknowledged me publicly, and paid $5,000 under the Dynamics 365 and Power Platform bounty program.
Pro Tip: Everybody and their cousin is hammering the main production app. That is the front door, and it has ten locks and a guard standing next to it. Go look at the forgotten stuff instead. The staging box, the dev subdomain, the old preview environment nobody remembers deploying. That is where the door is quietly unlocked. Recon wide, not just deep.
The RCE That Microsoft Refused to Call an RCE
This is the one. My favourite story of the whole year, and not because of the hack. Because of the fight that came after it.
It started the way a lot of good bugs do, with just reading. Reading traffic that everybody else scrolls right past.
I was going through the network requests of Microsoft's public advertising assets using HAR analysis. Think of it like a detective reading a phone bill. You record every single file the site quietly loads in the background, then you read the list line by line, hunting for the one thing that does not belong. And one line jumped out at me. The frontend was quietly asking for an internal npm package:
@bingads-webui-clientcenter/instrumentation
An internal package. Interesting. So I went over to the public npm registry and searched for that organization scope.
-
- Not found. It did not exist.
Huuh? Let me say that again, slowl. Microsoft's production ad platform, referenced across 40+ subdomains including ads.microsoft.com and bingads.microsoft.com, was depending on a package whose public namespace was sitting there, completely unclaimed.
And I stumbled onto this one in late November, right in the teeth of BSides 0x02 season. These things never show up when your calendar is clear.
This is a Dependency Confusion attack. Simplest way I can explain it. Imagine a company kitchen that orders its secret sauce ingredient from a private, in-house supplier. But the ordering system has one dumb rule baked in: always grab the newest version, private or public. So a stranger walks into the public market, puts up a jar with the exact same name, slaps a much higher version number on it, and waits. The system sees that higher number, assumes newer means better, and grabs the stranger's jar. Now the stranger's ingredients are going straight into the company's food.
Except the ingredients are code. And that code runs inside the company's build machines.
So I tested it, carefully and safely. I registered the empty scope, published a completely harmless proof of concept package with a very high version number (99.9.9), and set up a listener to see if anything phoned home.
45 minutes later, my listener lit up. DNS callbacks, coming from Microsoft Azure IP addresses.
Microsoft's own build infrastructure had reached out and touched my package. I was, in effect, inside. So I immediately unpublished the package to slam the door shut behind me, because the whole point was to prove the risk, not to become it.
I reported it as Critical RCE. And this is where the real story begins.
Microsoft first came back and classified it as "Spoofing." Severity: Important. Award: $2,500.
I read that and thought, respectfully, no. Spoofing means I pretended to be someone. That is not what happened here. What happened is that my code executed inside your pipeline. So I did the thing a lot of researchers are quietly scared to do. I appealed.
Not rudely, and not with a wall of ego. I wrote a calm, technical case. This is not spoofing, it is arbitrary code execution on your build infrastructure, and in every standard the industry uses, RCE outranks spoofing. I laid out the asset criticality and the supply chain risk in detail.
After an engineering review, they came back, and they agreed in part. They reclassified the impact from Spoofing to an RCE class pathway. That was a real win on its own. They held the overall severity at Important rather than Critical, because their bar for Critical needs conclusive proof of code executing inside the environment, and they felt my callback proved reach but not full execution. Fair enough. I still think it sat higher, but I respect a team that explains its reasoning instead of hiding behind a label.
And then came the part that made every single email worth it.
The reassessment went back to the bounty team. And they issued another $2,500. Same bug, award doubled, from $2,500 to $5,000. Purely because I did not accept the first number and I made my case like a professional.
Whatttt? Yes. My "no" was worth $2,500. That is the one lesson I want you to steal from this whole article.
The Ones That Got Away (And What They Taught Me)
Now let me sit in the part that actually hurts, because leaving it out would turn this into just another highlight reel.
Remember, more than 30 reports, and only 2 paid. So what happened to the rest?
Some got confirmed, fixed, and acknowledged. Real bugs, real impact, and zero money. Some came back "not applicable." And around five got far, far enough to be flagged for bounty review, before getting ruled out of scope.
Let me tell you what that last one feels like. You find something real. Your heart starts racing. You spend hours writing the perfect report, screenshots and reproduction steps and impact, all of it. The system confirms it, yes, this is a genuine bug. And then it tells you, but not one we are paying for. Out of scope. Nothing. No money, no leaderboard bump. Just a closed tab and a quiet lesson.
And those stung a little more that year, because every hour I spent hunting was an hour borrowed from the conference. A dead end did not just cost me a bounty. It cost me time I genuinely did not have.
Still, here is what those dead ends beat into me, the most important thing in this whole article after the appeal story. Scope decides the payout, not severity.
I found remote code execution on some of these targets. Actual RCE. And most of it paid nothing, because the asset sat outside the paid bounty scope. Meanwhile a "lower" information disclosure bug, sitting in exactly the right place, paid me $5,000. The bug being scary does not matter. The bug being in scope is the entire game.
So if you are new to this, tattoo it on your brain right now. A valid bug and a paid bug are two completely different things. Read the program scope first, before you fall in love with a finding. Not after. -_-
The 5 Lessons From a Year of Hunting Microsoft
Thirty-plus reports. Two payouts. $10,000. One conference. Here is what I actually walked away with.
1. The ratio is brutal, and that is completely normal. Two out of thirty-plus paid. Eleven reports at Azure, zero paydays. Seven RCE-class bugs, one payday. If you think real hunters land every bug, you have been reading marketing, not reality. The misses are the job.
2. Scope beats severity, every single time. My RCEs on out-of-scope assets earned nothing. My in-scope info disclosure earned five grand. Check the paid scope before you spend a weekend on a target.
3. Look where nobody else is looking. Both my wins came from the boring, forgotten corners. A staging server. A background network request most people scroll straight past. Everyone was hammering the front door while I was checking the side windows.
4. Learn to appeal, politely and with evidence. This is the big one. My appeal doubled a $2,500 bounty into $5,000 and got the impact reclassified. The first answer is not always the final answer. Make your case like a professional, then respect where it lands.
5. You do not have to do just one thing. I hunted Microsoft and ran a 25-person conference team in the same six months. Both suffered a little for it. Both also made me sharper. Running BSides taught me deadlines, delegation, and how to keep going when twenty other people are counting on you, and that discipline followed me straight back to the terminal.
The wins are real. The dead ends are more real. Anybody who only shows you the trophies is selling you something. This is the whole shelf, empty spaces and all.
Why This One Matters to Me
Let me get honest for a second, past the payloads.
I am not a company. No research lab, no security budget, no team of analysts feeding me targets. Just me, a laptop, in Dehradun, and a stubborn refusal to quit. And that exact setup went up against the systems of a company worth trillions, and their own security team put my name on their board.
That is what those two lines mean to me. Not the dollars. The proof that you do not need a badge from a big company to sit at the same table as one. If a BCA kid running recon between college classes and conference calls can land here, so can you. That is not a motivation poster. It is just what happened.
And that conference I keep mentioning? That is the other half of my year, and honestly the half I am proudest of. I ran the BSides Dehradun 0x02 edition, learned more from our first two editions than from almost anything else I did, and stood in front of a team of around 25 people trying to work out how you lead when you are still learning yourself. It slowed my hunting down. I would not trade it for double the bounties.
Because here is what both of those things have in common. Nobody gave me permission for either one. Not the hunting, not the conference. I just started, kept going, and figured it out in public, in front of everyone.
Oh, and that one case still sitting open? It is a good one. A full production takeover I have been going back and forth on for weeks now. I cannot say a word about it until Microsoft ships the fix and clears me to talk. But when they do, you already know where I am going to write it up.
Which brings me to the thing I actually want from you. We are building the third BSides Dehradun edition right now, up here in the mountains, for exactly these people. The hunters. The ones who will sit with one target for six hours straight. The independent researchers with no company behind them and nobody's permission to ask for. If that is you, come find me there in person. I would genuinely rather talk to you over a cup of chai than in a comment section.
Want to hack more?
I am building LeetSec, a home for the breakers and the builders. No fake screenshots, no "get rich in a week" nonsense. Just the real work, wins and dead ends both.
- Follow the Publication so you don't miss the next breakdown.
- Let's connect: LinkedIn | X (Twitter) | Instagram
(P.S. If you are grinding through your own pile of "out of scope" rejections right now, drop a comment and tell me where you are stuck. I read every single one. ^^)_
Happy hunting.