惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
IT之家
IT之家
博客园_首页
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
GbyAI
GbyAI
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
H
Help Net Security
T
Tailwind CSS Blog
B
Blog RSS Feed
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 叶小钗
雷峰网
雷峰网
量子位

BGR - Industry-Leading Insights In Tech And Entertainment

Here's How Much Your Original Macintosh From The '80s Is Worth Today This $10 Gadget On Amazon Adds 4 More USB Ports To Your Laptop 5 Things To Know Before Buying A Laptop Docking Station 11 Ways To Get The Most Out Of Your New PC 7 Of The Best Laptops For Seniors In 2026 Plastic Or Metal Laptop Body: Which Handles Heat Better? Windows Vs macOS: Which Is Better For You? Samsung's Next Laptop Lineup Might Be Abandoning Windows 11 The First Thing To Replace When Your PC Feels Outdated Stop Spending So Much On Second Monitors For Gaming - Do This Instead Amazon Is Selling 2026's Powerful MacBook Air For $150 Off Right Now 5 Ways You Can Speed Up A Slow SSD Laptops Vs. Notebooks: What's The Difference? Intel Is Reportedly Selling CPUs It Would Normally 'Scrap' Due To Overwhelming Demand 3 Common Mistakes People Make When Buying A Monitor Everything Microsoft Is Offering To Stop Students From Buying The MacBook Neo 5 Essential Tips For Cleaning And Maintaining Your PC Can You Use A Laptop Without A Battery? The Keyboard Accessory Most MacBook Owners Should Skip Here's How Much A Replacement Battery For The MacBook Neo Will Cost You How Often Should You Restart Your PC? Here's What Users Say What It Means If Your MacBook Charger Is Blinking Orange Don't Wait To Install Software Updates On Your Laptop - Here's Why Why Did Apple Get Rid Of The Touch Bar On The MacBook Pro? What Happened To IBM PCs? Why The Company Stopped Making Them RAM Prices Are Getting Too High In 2026, So This YouTuber Is Making His Own You Can Finally Get A Raspberry Pi Laptop - But Is It Worth It? Microsoft Says You Don't Need A Third-Party Antivirus App Anymore This Highly Rated 18-In-1 USB-C Hub Is $30 Off On Amazon Right Now 5 Clever Uses For Your PC's Secondary Monitor
AMD Refuses To Pay A $10,000 Bug Bounty For A Flaw It Nev...
Jonathan Sayers · 2026-06-15 · via BGR - Industry-Leading Insights In Tech And Entertainment
A sign displaying the AMD logo

Kevin Paul Davis/Shutterstock

The semiconductor company AMD operates a product security bug bounty program that awards up to $30,000 to security researchers who report a discovered vulnerability within AMD's products. But when a New Zealand researcher identified a remote code execution (RCE) vulnerability in AMD's AutoUpdate software, the company refused to pay the $10,000 bounty that this type of bug should have been worth.

The researcher in question is a 22-year-old programmer who goes by Paul. He posted about the situation on his MrBruh blog, where he details how he discovered the flaw and how easily a malicious party could exploit the RCE vulnerability to execute a man-in-the-middle (MITM) attack on your network. Despite the severity of this bug and the possibility that it could have affected millions of users, it took AMD a whopping 124 days to patch it — a fact that you might want to keep in mind when you're deciding whether Intel or AMD is better for your next computer.

AMD acknowledged Paul's findings and even took action based on his report, so why aren't they paying the bounty? Despite the fact that Paul drew attention to a major bug, the terms of the bounty program state that MITM attacks are outside the scope of the program. The report was closed, and to add salt to the wound, Paul was asked to remove his original blog post on the matter for an indefinite period.

What the AMD bug means for consumers

A laptop with stickers listing its internal components

Marvin Samuel Tolentino Pineda/Getty Images

Like any company, AMD has its ups and downs. They recently earned some goodwill after announcing that older AMD graphics cards will soon receive a free major upgrade. However, the situation surrounding Paul raises questions about AMD's consideration for its consumers and community members. The big question stemming from all of this is: Should you be worried about security if you have AMD components in your computer?

The good news is that AMD did patch the AutoUpdate bug that Paul brought to light. AMD published a CVE report on June 12 that includes details on the issue and actions taken. Before this fix, users were exposed to potential MITM attacks for as many as 124 days. This type of attack entails eavesdropping or even placing code directly between the target and the application they're using. This was made possible because malicious parties could perform a simple RCE to, as Paul explained, "replace the network response with any malicious executable of their choosing."

If you use AMD products with auto-update functionality, you might still be affected by the AMD bug that Paul discovered. In Paul's republished blog post about the RCE vulnerability, he recommends that AMD users should "uninstall everything" and download the latest versions of AMD software from the official website. And of course, you should always use security apps that actually protect your computer.