They NEVER pay
Eight years ago I got EL Reg to publish a warning about Outlook autodiscover handing out passwords to anyone who could get access to the website on the root of the domain. They said it wasn’t a security hole. Last year another person realised it was worse than I had realised (without knowing of my findings) and would hand credentials to anyone who registered autodiscover.com / .net / etc. they also told MS and also were told it wasn’t a security issue. Neither of us got even a thanks, let alone any recognition or bounty.
So is it not more important, and more morally correct to tell the wider world than to let MS leave a really quite large hole in their security for the best part of a decade?