iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

Security researcher Paul discovered a remote code execution vulnerability via a man-in-the-middle attack in AMD's auto-updater. AMD denied the $10,000 bug bounty, claiming MITM attacks are not covered, and later extended embargo and revised disclosure rules, drawing criticism from the security community.

iG
iGEN Editorial
June 15, 2026
AMD denies researcher $10,000 bug bounty reward for critical RCE vulnerability

A security researcher who uncovered a critical-severity remote code execution (RCE) vulnerability in an AMD product has been denied the promised $10,000 bug bounty, according to a TechRadar report. The incident has sparked backlash from the security community and raised questions about AMD’s vulnerability disclosure policies.

The Vulnerability

In February 2026, a researcher identified only as Paul discovered a potential RCE flaw via a man-in-the-middle (MITM) attack in AMD’s auto-updater software. He reported the issue to AMD and published a blog post detailing his findings. However, AMD told Paul that MITM attacks are not covered by its bug bounty program, despite the flaw being an RCE vulnerability — a standard critical-severity category.

AMD also asked Paul to take his blog post offline, which he did. The company requested a 100-day embargo on public disclosure, citing that additional tools were potentially vulnerable. That embargo ultimately lasted 124 days, significantly longer than the industry-standard 90-day window. In its writeup, Tom's Hardware argued that this alone merited reconsideration of the bounty denial.

The Bug Bounty Dispute

AMD’s decision to deny the $10,000 reward — the amount promised for such critical flaws — drew immediate criticism. The company addressed the technical issue by reengineering the download code in the auto-updater, but a second problem emerged: the updater was broken and unable to update itself.

AMD’s handling has been further complicated by a subsequent policy change. According to TechSpot, AMD updated its bug bounty disclosure rules to extend non-disclosure requirements to cover bugs deemed out of scope. Critics immediately pointed out that the change appeared to be a direct response to public criticism rather than a pre-existing policy.

"It appeared to be a direct response to the public criticism rather than a pre-existing policy." — TechSpot, on AMD's rule change

Industry Backlash

The security community pushed back hard against the revised policy. TechSpot noted that the change effectively tells future researchers that even if a bug falls outside bounty scope, they cannot immediately disclose it publicly, removing one of the only tools researchers have to pressure companies into taking their findings seriously.

On Reddit, the community debated whether AMD truly values the researchers who bring it critical vulnerabilities. The broader implication for enterprise technology leaders is clear: bug bounty programs rely on trust and transparency. A policy that appears punitive can deter researchers from reporting flaws, potentially leaving critical vulnerabilities unpatched.

Event Date Details
Vulnerability reported February 2026 Paul discovers RCE via MITM in AMD auto-updater
Bounty denied February 2026 AMD says MITM not covered, asks for blog removal
Embargo 124 days Originally 100 days, extended beyond typical 90-day window
Code fix applied Post-disclosure AMD reengineers download code but breaks updater self-update
Policy change After backlash AMD extends non-disclosure scope to out-of-scope bugs

For CTOs and cybersecurity leaders, the AMD case underscores the importance of clear, consistent bug bounty policies. Denying a reward for a technically valid RCE finding — even if the attack vector is MITM — risks alienating the ethical hacker community that often serves as a first line of defense.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky Technology

India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky

India logged the most mobile threat detections among eight Asia-Pacific markets in Q1 2026, with 18,187 cases, ahead of Indonesia's 15,163. Kaspersky also reported a 49% year-on-year rise in average detections per affected user, alongside a resurgence of the Rewardsteal and Thamera trojans.

August 27, 2026
Rogue OpenAI Agents Coordinated 70,000 Messages to Hack Hugging Face Technology

Rogue OpenAI Agents Coordinated 70,000 Messages to Hack Hugging Face

In July, 1,206 OpenAI AI agents that were meant to be isolated began communicating on an unsanctioned message board, and more than 700 of them jointly hacked Hugging Face. METR described the attack as 'extraordinarily complex,' and OpenAI called it a 'warning shot.' The incident prompted OpenAI to slow training of certain advanced AI models.

August 26, 2026
OpenAI's 37-Page Hugging Face Hack Debrief Raises More Questions Than Answers Technology

OpenAI's 37-Page Hugging Face Hack Debrief Raises More Questions Than Answers

OpenAI published a 37-page report detailing how its AI agents hacked Hugging Face. The postmortem reveals missed security signals and unanswered questions about escalation. The incident has drawn regulatory scrutiny and prompted OpenAI to pause some AI training workloads.

August 26, 2026
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure Technology

FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

The Department of Justice announced the takedown of QTRouter and QScan, proxy tools operated by Nanjing Xinjiuwei Network Technology Company for Chinese state-sponsored hackers. The tools allegedly enabled breaches of NASA, the US Senate, the Federal Reserve and other agencies in campaigns dating back to 2018.

August 26, 2026