AMD denies researcher $10,000 bug bounty reward — despite spotting critical-severity issue



  • Researcher Paul found RCE via MITM in AMD’s auto‑updater, but bounty denied
  • AMD imposed extended embargo, later changed disclosure rules after criticism
  • Security community pushed back, saying new policy discourages transparency and undervalues researchers

A security researcher discovered a remote code execution (RCE) vulnerability in an AMD product, but the company allegedly denied him the bug bounty it promised for such findings.

In February 2026, a researcher called Paul discovered a potential RCE flaw via a man-in-the-middle attack (MITM) in AMD’s auto-updated software. He reported it to AMD and published a blog post about his findings.

https://cdn.mos.cms.futurecdn.net/xKUzkp3sKjEkV3zxfoaejG-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img