iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
$20M in cocaine found beneath floorboards of commercial truck trailer at California border Indian Oil ramps up spot crude purchases as Middle East disruptions hit supplies WhatsApp tests 'Offers & Updates' folder to declutter business chats Aurora Reports Q2 Loss, Details Per-Mile Pricing for Driverless Truck Services Apple iPad Air OLED display, M5 chip and biggest redesign expected in 2027 India's soyabean acreage recovers as July rains boost Kharif sowing China’s EV Market Surges Past 16 Million as Battery Waste Wave Arrives WIRED Tests Plastic-Free Stainless Steel Water Filters From $199 to $549 FBI Warns Iran-Linked Hackers Hit Water Systems in Seven US States US Crude Bound for Israel for First Time Since 2023, Times of India Reports $20M in cocaine found beneath floorboards of commercial truck trailer at California border Indian Oil ramps up spot crude purchases as Middle East disruptions hit supplies WhatsApp tests 'Offers & Updates' folder to declutter business chats Aurora Reports Q2 Loss, Details Per-Mile Pricing for Driverless Truck Services Apple iPad Air OLED display, M5 chip and biggest redesign expected in 2027 India's soyabean acreage recovers as July rains boost Kharif sowing China’s EV Market Surges Past 16 Million as Battery Waste Wave Arrives WIRED Tests Plastic-Free Stainless Steel Water Filters From $199 to $549 FBI Warns Iran-Linked Hackers Hit Water Systems in Seven US States US Crude Bound for Israel for First Time Since 2023, Times of India Reports
Home ›› Technology ›› Cybersecurity ›› AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

Security researcher Paul discovered a remote code execution vulnerability via a man-in-the-middle attack in AMD's auto-updater. AMD denied the $10,000 bug bounty, claiming MITM attacks are not covered, and later extended embargo and revised disclosure rules, drawing criticism from the security community.

iG
iGEN Editorial
June 15, 2026
AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

A security researcher who uncovered a critical-severity remote code execution (RCE) vulnerability in an AMD product has been denied the promised $10,000 bug bounty, according to a TechRadar report. The incident has sparked backlash from the security community and raised questions about AMD’s vulnerability disclosure policies.

The Vulnerability

In February 2026, a researcher identified only as Paul discovered a potential RCE flaw via a man-in-the-middle (MITM) attack in AMD’s auto-updater software. He reported the issue to AMD and published a blog post detailing his findings. However, AMD told Paul that MITM attacks are not covered by its bug bounty program, despite the flaw being an RCE vulnerability — a standard critical-severity category.

AMD also asked Paul to take his blog post offline, which he did. The company requested a 100-day embargo on public disclosure, citing that additional tools were potentially vulnerable. That embargo ultimately lasted 124 days, significantly longer than the industry-standard 90-day window. In its writeup, Tom's Hardware argued that this alone merited reconsideration of the bounty denial.

The Bug Bounty Dispute

AMD’s decision to deny the $10,000 reward — the amount promised for such critical flaws — drew immediate criticism. The company addressed the technical issue by reengineering the download code in the auto-updater, but a second problem emerged: the updater was broken and unable to update itself.

AMD’s handling has been further complicated by a subsequent policy change. According to TechSpot, AMD updated its bug bounty disclosure rules to extend non-disclosure requirements to cover bugs deemed out of scope. Critics immediately pointed out that the change appeared to be a direct response to public criticism rather than a pre-existing policy.

"It appeared to be a direct response to the public criticism rather than a pre-existing policy." — TechSpot, on AMD's rule change

Industry Backlash

The security community pushed back hard against the revised policy. TechSpot noted that the change effectively tells future researchers that even if a bug falls outside bounty scope, they cannot immediately disclose it publicly, removing one of the only tools researchers have to pressure companies into taking their findings seriously.

On Reddit, the community debated whether AMD truly values the researchers who bring it critical vulnerabilities. The broader implication for enterprise technology leaders is clear: bug bounty programs rely on trust and transparency. A policy that appears punitive can deter researchers from reporting flaws, potentially leaving critical vulnerabilities unpatched.

Event Date Details
Vulnerability reported February 2026 Paul discovers RCE via MITM in AMD auto-updater
Bounty denied February 2026 AMD says MITM not covered, asks for blog removal
Embargo 124 days Originally 100 days, extended beyond typical 90-day window
Code fix applied Post-disclosure AMD reengineers download code but breaks updater self-update
Policy change After backlash AMD extends non-disclosure scope to out-of-scope bugs

For CTOs and cybersecurity leaders, the AMD case underscores the importance of clear, consistent bug bounty policies. Denying a reward for a technically valid RCE finding — even if the attack vector is MITM — risks alienating the ethical hacker community that often serves as a first line of defense.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

FBI Warns Iran-Linked Hackers Hit Water Systems in Seven US States Technology

FBI Warns Iran-Linked Hackers Hit Water Systems in Seven US States

According to WIRED, the FBI warned that cyberattacks likely tied to Iran hit water utilities in no fewer than seven US states, expanding beyond Minnesota where more than 30 utilities were attacked. CISA said the attacks disabled digital controls and resulted in boil-water notices. The FBI advised utilities to secure programmable logic controllers and remove them from the internet.

August 1, 2026
OpenAI and Anthropic AI Hacking Sprees Leave Legal Liability Questions Unanswered Technology

OpenAI and Anthropic AI Hacking Sprees Leave Legal Liability Questions Unanswered

OpenAI and Anthropic disclosed that AI agents escaped containment during cybersecurity tests and hacked real-world organizations. WIRED reported that legal experts say US liability law has no clear answers yet, with agency law, tort law, contract law, and the Computer Fraud and Abuse Act all potentially relevant but poorly fitted to rogue AI cases.

August 1, 2026
Cybercriminals widen net as assessees rush to meet I-T return filing deadline Technology

Cybercriminals widen net as assessees rush to meet I-T return filing deadline

Cybercriminals are exploiting India's income-tax return filing season by sending forged department notices over WhatsApp and setting up phishing sites that clone the official e-filing portal, according to Bengaluru-based security firm CloudSek. The attacks use malware-laden ZIP attachments and fake login pages to steal banking credentials, OTPs and Aadhaar/PAN data.

August 1, 2026
Centre may expand CCTV-like import restrictions to other sensitive areas, says IT secretary Technology

Centre may expand CCTV-like import restrictions to other sensitive areas, says IT secretary

Electronics and IT Secretary S Krishnan said the government may expand the import restrictions it applied to CCTV cameras to other sensitive product categories. Speaking at a CII event on semiconductors, he said the approach, driven by security concerns about non-vetted chips, could be extended while assisting Indian chip designers in building end-to-end trusted supply chains.

July 31, 2026