I found and reported a security issue to Microsoft. They responded nearly right away and it was a real person . I was soon talking directly to the right team to explain it to. I provided assets required to replicate and they jumped right on it and fixed it. They even told me what KB* it was resolved in via follow up email. I didn’t want any kind of monetary reward - just happy to have it fixed. I regularly report security issues in open source projects too. Now, I also once tried to report a fairly serious issue that impacted iOS and MacOS X (at the time) and you’d have thought (naively) they’d have been super interested and helpful as Microsoft were. Wrong. In fact their first response basically meant I never ended up getting past their first auto reply.