ended6월 13일· 1 sources
AMD's Insecure Auto-Updater Exposed Millions to Malware, but Researcher Got No Reward
AMD의 무책임한 보안 대응: 결함 발견자에게 보상 거부
Why it matters
AMD's auto-updater flaw allowed attackers to inject malware into millions of systems through unencrypted HTTP downloads, yet the company refused to compensate the researcher who discovered it. The incident exposes how tech vendors exploit policy loopholes to avoid bounties while dragging patch timelines well beyond industry standards—taking 124 days instead of the recommended 5-14 days for critical vulnerabilities. Even more troubling, the final patch relied on weak CRC32 checksums rather than cryptographic signatures, suggesting deeper systemic security failures that remain unaddressed.
1
Sources
+0
24h
—
Growth
90d
Active
AMD securityCode executionMan-in-the-middleHTTP vulnerabilityBug bounty