Microsoft has expanded its bug bounty programs to cover the open-source.NET Core and ASP.NET Core application development platforms. Microsoft will pay US$500 to $15,000 for critical vulnerabilities in the RTM (release to manufacturing), Beta, or RC (release candidate) releases of these platforms. The company also rewards researchers for finding novel exploitation techniques against the protections built into Windows, as well as for defensive ideas that can lead to new exploit mitigations. Microsoft’s cross-platform Kestrel web server is also covered by the program.”]