惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

BGR - Industry-Leading Insights In Tech And Entertainment

4 Features To Look For In Your Next Phone Case The Apple Watch Series 11 Is Great, But Smart Money Buys This Smartwatch Instead 4 Of The Most Useful Gadgets For Seniors (Besides Phones) Is It Safe To Plug Your Phone Into A USB Wall Socket? 5 Ways To Speed Up Your MacBook Neo 5 Myths About Incognito Mode You Need To Stop Believing Here's How Much The MacBook Neo's Display Costs To Replace 5 Of The Best Nintendo Switch 2 Carrying Cases New Breakthrough In Quantum Computers Could Completely Change How Much They Cost 5 3D Printer Projects To Take Your Raspberry Pi Builds To The Next Level What Makes The Apple Pencil So Expensive? 5 Notoriously Unreliable Retro Consoles You Should Avoid Why You Can't Just Buy A Petabyte Hard Drive 4 Reliable USB Charger Brands That Can Compete With Anker There Might Be A Drawback To Using Your Roku On A Monitor 5 Email Etiquette Rules People Break All The Time Here's What Those Two Holes Are For On Your Samsung Galaxy Phone Cheap Projectors Will Probably Leave You Disappointed - Here's Why 5 Weird Raspberry Pi Projects That Will Freak Out Your Friends What's The Point Of A Mini PC If You Already Have A Laptop? Yellowstone Star Wes Bentley Explored Deep Space In A Beloved Sci-Fi Movie 7 Renter-Friendly Smart Home Upgrades Your Landlord Won't Mind This Palm-Sized Camera Gadget Is The Secret To Capturing Perfect Lightning Strikes Upstream Vs. Downstream USB Ports On Your Monitor: What's The Difference? 4 Of The Coolest Gadgets For Your Xbox Don't Wait To Upgrade Your MacBook In 2026 - Here's Why Should You Accept Or Reject Cookies From A Website? 5 Gaming Monitors That Are Perfect For Your PlayStation 5 What A Smart Thermostat Actually Saves You Money On (And What It Doesn't) 5 USB-Powered Gadgets That Can Replace Traditional Appliances
AMD Refuses To Pay A $10,000 Bug Bounty For A Flaw It Nev...
Jonathan Sayers · 2026-06-15 · via BGR - Industry-Leading Insights In Tech And Entertainment
A sign displaying the AMD logo

Kevin Paul Davis/Shutterstock

The semiconductor company AMD operates a product security bug bounty program that awards up to $30,000 to security researchers who report a discovered vulnerability within AMD's products. But when a New Zealand researcher identified a remote code execution (RCE) vulnerability in AMD's AutoUpdate software, the company refused to pay the $10,000 bounty that this type of bug should have been worth.

The researcher in question is a 22-year-old programmer who goes by Paul. He posted about the situation on his MrBruh blog, where he details how he discovered the flaw and how easily a malicious party could exploit the RCE vulnerability to execute a man-in-the-middle (MITM) attack on your network. Despite the severity of this bug and the possibility that it could have affected millions of users, it took AMD a whopping 124 days to patch it — a fact that you might want to keep in mind when you're deciding whether Intel or AMD is better for your next computer.

AMD acknowledged Paul's findings and even took action based on his report, so why aren't they paying the bounty? Despite the fact that Paul drew attention to a major bug, the terms of the bounty program state that MITM attacks are outside the scope of the program. The report was closed, and to add salt to the wound, Paul was asked to remove his original blog post on the matter for an indefinite period.

What the AMD bug means for consumers

A laptop with stickers listing its internal components

Marvin Samuel Tolentino Pineda/Getty Images

Like any company, AMD has its ups and downs. They recently earned some goodwill after announcing that older AMD graphics cards will soon receive a free major upgrade. However, the situation surrounding Paul raises questions about AMD's consideration for its consumers and community members. The big question stemming from all of this is: Should you be worried about security if you have AMD components in your computer?

The good news is that AMD did patch the AutoUpdate bug that Paul brought to light. AMD published a CVE report on June 12 that includes details on the issue and actions taken. Before this fix, users were exposed to potential MITM attacks for as many as 124 days. This type of attack entails eavesdropping or even placing code directly between the target and the application they're using. This was made possible because malicious parties could perform a simple RCE to, as Paul explained, "replace the network response with any malicious executable of their choosing."

If you use AMD products with auto-update functionality, you might still be affected by the AMD bug that Paul discovered. In Paul's republished blog post about the RCE vulnerability, he recommends that AMD users should "uninstall everything" and download the latest versions of AMD software from the official website. And of course, you should always use security apps that actually protect your computer.