ended6월 13일· 1 sources

AMD's Insecure Auto-Updater Exposed Millions to Malware, but Researcher Got No Reward

AMD의 무책임한 보안 대응: 결함 발견자에게 보상 거부

Why it matters

AMD's auto-updater flaw allowed attackers to inject malware into millions of systems through unencrypted HTTP downloads, yet the company refused to compensate the researcher who discovered it. The incident exposes how tech vendors exploit policy loopholes to avoid bounties while dragging patch timelines well beyond industry standards—taking 124 days instead of the recommended 5-14 days for critical vulnerabilities. Even more troubling, the final patch relied on weak CRC32 checksums rather than cryptographic signatures, suggesting deeper systemic security failures that remain unaddressed.

1
Sources
+0
24h
Growth
90d
Active
AMD securityCode executionMan-in-the-middleHTTP vulnerabilityBug bounty

Sources

Related Issues