PulseAugur
EN
LIVE 09:31:40

AMD denies bug bounty for critical auto-updater flaw after 124-day fix

AMD has denied a security researcher a $10,000 bug bounty for discovering a critical vulnerability in its auto-updater software. The researcher, Paul, reported the flaw in February, which could have allowed for remote code execution via a man-in-the-middle attack. Despite AMD's request to temporarily take down his blog post detailing the issue, the company took 124 days to implement a fix and did not offer any bounty payment, citing program policy limitations. AI

IMPACT This incident highlights potential issues in how tech companies handle bug reporting and bounty programs, which could affect researcher trust and software security practices.

RANK_REASON This is a story about a company's internal policy and a dispute over a bug bounty, not a new product release or significant industry-wide event.

Read on Tom's Hardware →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

AMD denies bug bounty for critical auto-updater flaw after 124-day fix

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
This is a story about a company's internal policy and a dispute over a bug bounty, not a new product release or significant industry-wide event.
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
Standard
On-topic for AI-industry coverage; kept in the public index.
Story freshness
89 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

Full methodology in our editorial standards.

COVERAGE [2]

  1. Tom's Hardware TIER_1 English(EN) · Bruno Ferreira ·

    AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch

    AMD took over four months to fix a critical security bug in its autoupdater, and the security researcher didn't see a dime for his efforts

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch AMD took over four months to

    AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch AMD took over four months to fix a critical security bug in its autoupdater, and the security researcher didn't see a dime for his efforts https://ww…