iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
NewCore Emerges with $66M to Give AI Agents Identities as Digital Workers U.S.-Iran Peace Deal Reopens Strait of Hormuz, Unleashing Global Oil Supply How hackers allegedly stole $1.7 million worth of condoms from a Walmart shipment FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards Rupee rallies to five-week high on crude oil plunge; RBI measures add to momentum India Pitches Quantum Computing Collaboration with Russia Under National Mission at BRICS Forum Google TV's Gemini Voice Assistant Now Controls Picture Settings on TCL TVs Nvidia Still Dominates GPU Market but AMD's Radeon RX 9070 XT Gains Traction in Steam Survey AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability Petrobras Awards $88.75M Decommissioning Contract to OceanPact for Marlim Field NewCore Emerges with $66M to Give AI Agents Identities as Digital Workers U.S.-Iran Peace Deal Reopens Strait of Hormuz, Unleashing Global Oil Supply How hackers allegedly stole $1.7 million worth of condoms from a Walmart shipment FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards Rupee rallies to five-week high on crude oil plunge; RBI measures add to momentum India Pitches Quantum Computing Collaboration with Russia Under National Mission at BRICS Forum Google TV's Gemini Voice Assistant Now Controls Picture Settings on TCL TVs Nvidia Still Dominates GPU Market but AMD's Radeon RX 9070 XT Gains Traction in Steam Survey AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability Petrobras Awards $88.75M Decommissioning Contract to OceanPact for Marlim Field
Home ›› Technology ›› Cybersecurity ›› AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

Security researcher Paul discovered a remote code execution vulnerability via a man-in-the-middle attack in AMD's auto-updater. AMD denied the $10,000 bug bounty, claiming MITM attacks are not covered, and later extended embargo and revised disclosure rules, drawing criticism from the security community.

iG
iGEN Editorial
June 15, 2026
AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

A security researcher who uncovered a critical-severity remote code execution (RCE) vulnerability in an AMD product has been denied the promised $10,000 bug bounty, according to a TechRadar report. The incident has sparked backlash from the security community and raised questions about AMD’s vulnerability disclosure policies.

The Vulnerability

In February 2026, a researcher identified only as Paul discovered a potential RCE flaw via a man-in-the-middle (MITM) attack in AMD’s auto-updater software. He reported the issue to AMD and published a blog post detailing his findings. However, AMD told Paul that MITM attacks are not covered by its bug bounty program, despite the flaw being an RCE vulnerability — a standard critical-severity category.

AMD also asked Paul to take his blog post offline, which he did. The company requested a 100-day embargo on public disclosure, citing that additional tools were potentially vulnerable. That embargo ultimately lasted 124 days, significantly longer than the industry-standard 90-day window. In its writeup, Tom's Hardware argued that this alone merited reconsideration of the bounty denial.

The Bug Bounty Dispute

AMD’s decision to deny the $10,000 reward — the amount promised for such critical flaws — drew immediate criticism. The company addressed the technical issue by reengineering the download code in the auto-updater, but a second problem emerged: the updater was broken and unable to update itself.

AMD’s handling has been further complicated by a subsequent policy change. According to TechSpot, AMD updated its bug bounty disclosure rules to extend non-disclosure requirements to cover bugs deemed out of scope. Critics immediately pointed out that the change appeared to be a direct response to public criticism rather than a pre-existing policy.

"It appeared to be a direct response to the public criticism rather than a pre-existing policy." — TechSpot, on AMD's rule change

Industry Backlash

The security community pushed back hard against the revised policy. TechSpot noted that the change effectively tells future researchers that even if a bug falls outside bounty scope, they cannot immediately disclose it publicly, removing one of the only tools researchers have to pressure companies into taking their findings seriously.

On Reddit, the community debated whether AMD truly values the researchers who bring it critical vulnerabilities. The broader implication for enterprise technology leaders is clear: bug bounty programs rely on trust and transparency. A policy that appears punitive can deter researchers from reporting flaws, potentially leaving critical vulnerabilities unpatched.

Event Date Details
Vulnerability reported February 2026 Paul discovers RCE via MITM in AMD auto-updater
Bounty denied February 2026 AMD says MITM not covered, asks for blog removal
Embargo 124 days Originally 100 days, extended beyond typical 90-day window
Code fix applied Post-disclosure AMD reengineers download code but breaks updater self-update
Policy change After backlash AMD extends non-disclosure scope to out-of-scope bugs

For CTOs and cybersecurity leaders, the AMD case underscores the importance of clear, consistent bug bounty policies. Denying a reward for a technically valid RCE finding — even if the attack vector is MITM — risks alienating the ethical hacker community that often serves as a first line of defense.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

How hackers allegedly stole $1.7 million worth of condoms from a Walmart shipment Technology

How hackers allegedly stole $1.7 million worth of condoms from a Walmart shipment

A shipment of ONE Condoms and Move lubricant worth $1.7 million was allegedly stolen after hackers used a phishing email to impersonate a legitimate trucking carrier. The cargo was rerouted to a Bronx warehouse instead of a Walmart distribution center in Pennsylvania. The FBI reported that cyber-enabled cargo theft losses in the US and Canada reached nearly $725 million in 2025, up 60% from the previous year.

June 15, 2026
FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards Technology

FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards

The FBI dismantled a Chinese phishing-as-a-service operation called Outsider Enterprise, seizing servers, cryptocurrency, and a Telegram bot. The three-year-old service generated around 9,000 fake websites and over a million fraudulent URLs, resulting in theft of 3.8 million credit card records and $1.9 billion in losses. Google filed a civil lawsuit and reported that criminals sent 2.5 million fraudulent SMS messages in just two weeks.

June 15, 2026
Nvidia Still Dominates GPU Market but AMD's Radeon RX 9070 XT Gains Traction in Steam Survey Technology

Nvidia Still Dominates GPU Market but AMD's Radeon RX 9070 XT Gains Traction in Steam Survey

According to Valve's latest Steam Hardware Survey, AMD's Radeon RX 9070 XT has suddenly become the most popular AMD GPU with a 1.33% market share, surpassing Nvidia's RTX 4070 Ti. However, Nvidia still dominates the desktop GPU market, led by the RTX 3060. The survey provides a limited but interesting glimpse into hardware preferences, though it focuses on gaming rather than enterprise applications.

June 15, 2026
Why Your Help Desk Remains the Biggest Security Risk in Your Organization Technology

Why Your Help Desk Remains the Biggest Security Risk in Your Organization

TechRadar reports that help desk social engineering attacks, like those that hit MGM Resorts, Marks & Spencer, and Harrods, bypass most security controls. AI has amplified the threat, with phishing scams up 85% and average losses doubling to $2,060. Best practices include hardening identity operations and tying device enrollment to identity.

June 15, 2026