惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
L
LangChain Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
Martin Fowler
Martin Fowler
月光博客
月光博客
Y
Y Combinator Blog
U
Unit 42
D
Docker
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Gadget Review

Bernie Sanders Wants You to Own Half of OpenAI - And He's Not Kidding - Gadget Review California Bill Strikes Back Against Disappearing Video Games - Gadget Review Japan Cracks 6G's Speed Barrier With 112 Gbps Wireless Breakthrough - Gadget Review 31 Amazon Kitchen Tools and Gadgets That Make Prep Time a Breeze The 559-Mile Mic-Drop: Why BMW’s New i3 Just Made Tesla’s Range Look Like A Toy - Gadget Review 20 Genius Camping Gadgets That Will Help Make Summer Camping Easier Tesla Patents Transform Glass Roofs Into Smart Air Conditioners - Gadget Review Is Anthropic’s “Benefit Corp” Structure An Investor’s Worst Nightmare? - Gadget Review How An AI Weather Startup Just Beat the World’s Greatest Supercomputers - Gadget Review Dell's New XPS 13 Is Directly Targeting The MacBook Neo - Gadget Review 13 Smart Home Gadgets for True Local Control (No Cloud Needed!) Florida Sues OpenAI and CEO Sam Altman - Why Florida Is Treating AI Chatbots as "Hazardous Products" - Gadget Review Malaysia’s Scorched-Earth Policy Against Under-16 Social Media Access - Ban Carries Fines Up To $2.5 Million - Gadget Review PlayStation's Wireless Fight Stick and Latest Gaming Monitor Hits This August - Gadget Review How Meta's Chatbot Handed Over Million-Dollar Instagram Accounts To Attackers - Gadget Review 11 Home Security Gadgets That Help Safeguard Your Sanctuary Engineer Builds AI-Powered Laser System That Targets & Hunts Mosquitoes at Home - Gadget Review DuckDuckGo's No-AI Search Extensions Surge as Users Flee Google's AI Overhaul - Gadget Review Google Wants to Release 32 Million "Infected" Mosquitoes Into The Wild - Gadget Review Nvidia Is Bringing AI Power To Your Desk With New Superchip - Gadget Review Tech CEOs Are Using AI as the Perfect Scapegoat for Mass Layoffs - Gadget Review Wix Cuts 1,000 Jobs, Citing AI Evolution and Currency Pressures - Gadget Review Teen's Bluetooth Speaker Named "BOMB" Forces Flight U-Turn Mid-Atlantic - Gadget Review China's Humanoid Robots Sort 1,200 Postal Packages Per Hour - Gadget Review California Senate Passes Historic Ban on AI Chatbot Toys - Gadget Review Professor Declares War on AI: Will Fail Any Student Who Uses It - Gadget Review UK Military Looks At Allowing Lethal Strikes With Zero Human Intervention - Gadget Review Chinese EVs Are Tanking in Value - Gadget Review Japanese Researchers Create Chip That Could Run 1,000x Faster, Near-Zero Heat - Gadget Review Total Immobility: Why A Single Targeted Cyberattack Could Leave Every EV In Your City Stranded - Gadget Review
AMD Stiffs Researcher $10,000 Bug Bounty After Critical S...
Al Landes · 2026-06-13 · via Gadget Review

AMD refused $10,000 bounty to researcher Paul LaRosa despite fixing HTTP vulnerability in Windows auto-updater

Finding a critical security vulnerability should get you rewarded, not stiffed. AMD’s auto-updater was downloading software over insecure HTTP connections, letting network attackers slip malicious code onto your system during routine updates. The researcher who found this remote code execution flaw expected a $10,000 bounty. Instead, AMD fixed the problem after four months and paid nothing.

The Flaw That Could Own Your System

A trusted update process became an open highway for malware delivery.

Paul LaRosa discovered that AMD’s Windows auto-updater—used by Ryzen Master and other utilities—was grabbing updates through unencrypted HTTP connections. Anyone positioned on your network could perform a man-in-the-middle attack, swapping legitimate driver downloads with malware. Think of it like ordering food delivery but letting strangers intercept and replace your meal between the restaurant and your door. Your system would happily install whatever the attacker served up, believing it came from AMD.

This affects you if you’ve used AMD utilities that handle automatic updates. The vulnerability created a highway for attackers to achieve remote code execution, essentially gaining control of your machine through what should be a trusted update process.

Four Months of “Just a Little More Time”

What started as a 90-day disclosure window stretched into a four-month waiting game.

AMD acknowledged the flaw was real but refused the bounty, citing policy exclusions for man-in-the-middle attacks. The company asked LaRosa to delay public disclosure in February, promising a fix within 90 days—standard practice in security research. Then AMD asked for more time. Then more again. The final patch arrived 124 days after the initial report.

Compare that timeline to security best practices: critical vulnerabilities should be patched within 5-14 days, not over four months. It’s like your doctor finding cancer and scheduling treatment for next season. Some flaws demand urgency, especially those affecting automatic update mechanisms that users trust to keep them secure.

Still Using Weak Security After the “Fix”

The patch solved one problem but left deeper security weaknesses untouched.

AMD reengineered the auto-updater to use encrypted downloads, but the fix reveals deeper problems. The updated software still validates downloaded files using CRC32—a checksum that’s about as secure as a screen door. Modern software should use cryptographically signed updates that can’t be forged, not checksums that determined attackers can manipulate.

This case exposes how major vendors handle security: fix the immediate problem, avoid paying researchers through policy loopholes, and leave underlying weaknesses in place. You’re left wondering which other “secure” auto-updaters are similarly vulnerable, and whether companies care more about their bug bounty budget than your system security.