- What: AMD faces backlash over bug bounty denial
- Impact: Security researchers and disclosure policies
Bug Bounties AMD faces backlash over alleged bug bounty denial and changed disclosure rules June 16, 2026 Share By SC Staff Adobe Stock Based on information from Tech Radar, a security researcher has sparked controversy after AMD allegedly denied a bug bounty for a critical remote code execution (RCE) vulnerability discovered in the company's auto-updater software. The situation has escalated with criticism directed at AMD's handling of the disclosure and subsequent changes to its bug bounty program rules. A researcher identified as Paul reportedly found a remote code execution flaw via a man-in-the-middle attack in AMD's auto-updater. Despite reporting the vulnerability, AMD reportedly denied the $10,000 bug bounty, claiming man-in-the-middle attacks were outside the scope of their program, even though the flaw allowed for RCE. This occurred after an extended 124-day embargo period, significantly longer than the standard 90 days, during which AMD addressed the vulnerability by reengineering the download code, the researcher said. Following public criticism, AMD allegedly revised its disclosure rules, extending non-disclosure requirements to bugs deemed out of scope. This move has drawn sharp criticism from the security community, who argue it discourages transparency and undervalues researchers' contributions, potentially hindering public disclosure of critical vulnerabilities. Source: Tech Radar SC Staff Related Vulnerability Management Microsoft awards $2.3 million in Zero Day Quest hacking contest SC Staff April 16, 2026 The Zero Day Quest saw participation from researchers across more than 20 countries. Security Operations UIDAI launches bug bounty program to secure Aadhaar ecosystem SC Staff March 16, 2026 The UIDAI bug bounty initiative involves a panel of 20 selected security researchers who will assess critical digital platforms, including the official website, myAadhaar portal, and the Secure QR Code application. Bug Bounties Google awards over $17 million to security researchers in 2025 SC Staff March 13, 2026 The company's VRP has awarded over $81.6 million in total since its inception in 2010. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds