← Feed Deep Dive Matrix Subscribe

AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability

tomshardware.com 2026-06-12 Bruno Ferreira
Entities
Companies:AMD
People:Paul
Tags
Bug BountySecurity ResearchAMDAuto-updaterRemote Code ExecutionMITM AttackCVESoftware SecurityVulnerability DisclosureCybersecurityRCE VulnerabilityPatch Management
News Summary
AMD has come under fire for denying a $10,000 bug bounty to a security researcher who identified a critical remote code execution (RCE) vulnerability in the company’s auto-updater software. Although t... Read original →
Industry Analysis
AMD’s bounty denial reveals a deeper flaw: the semiconductor industry’s systemic neglect of software integrity. Technically, clinging to CRC32—a non-cryptographic hash—leaves firmware update chains vulnerable across OEMs and cloud infrastructures. Compliance-wise, ambiguous bounty policies erode researcher trust and may trigger regulatory scrutiny over hardware vendors’ software security practices, raising disclosure costs industry-wide. Competitors like NVIDIA and Intel could capitalize by proactively publishing secure update protocols to win enterprise confidence. Over the next 12–24 months, with EU’s Cyber Resilience Act and new SEC rules taking effect, treating software as an afterthought will jeopardize market access and ESG ratings. Security is no longer optional—it’s a gatekeeping requirement.
Read Original Article →
Related
This page displays AI-generated summaries and metadata for research purposes. Original content belongs to the respective publishers.