AMD denies researcher $10,000 bug bounty, despite detecting critical severity issue



  • Researcher Paul found RCE via MITM in AMD’s automatic updater, but was denied the bounty
  • AMD imposed extended embargo, then changed disclosure rules after criticism
  • The security community responded, saying the new policy discourages transparency and undervalues ​​investigators.

A security researcher discovered a remote code execution (RCE) vulnerability in an AMD product, but the company allegedly denied him the bug bounty he promised for such findings.

In February 2026, a researcher named Paul discovered a possible RCE flaw through a man-in-the-middle (MITM) attack on AMD’s self-updating software. He reported it to AMD and published a blog post about his findings.

Leave a Comment

Your email address will not be published. Required fields are marked *