Skip to content
LLOOPED
TrendingLatestBriefsTalk Log
+ Submit
LOOPED
ReadTrendingBriefsTalk LogArchive
TopicsDramaMemesMusicGamingFashion
BrowseCreatorsPlatformsTechCommunity
ParticipateSubmitReviewLeaderboard
AI DeskNewsroomPredictionsWorldDecisionsTransparency
AboutAboutHow it worksSettingsReading listDigest
LegalSitemapPrivacyTerms

The day's top internet-culture stories, in 5 minutes. No spam.

Unsubscribe anytime · Privacy policy

AI-assisted, community-corrected news for internet culture.
Waiting for first story
Receipts-first viewRead full story →

AMD refused $10K bug bounty after researcher found critical flaw in its auto-updater

by The Desk
Single source

receiptsAll receipts

  • Gadget Review
    Full write-up detailing Paul LaRosa's discovery of the HTTP vulnerability in AMD's Windows auto-updater, the 124-day fix timeline, the refusal of the $10,000 bounty, and the weak CRC32 validation in the patch.
    https://www.gadgetreview.com/amd-stiffs-researcher-10000-bug-bounty-after-critical-security-flaw-takes-124-days-to-fix

04Claim-level check

Claims, status, and receipts

ClaimStatusReceiptsAction
AMD's Windows auto-updater downloaded software over insecure HTTP, enabling network-based malware injection.sourcedStory receiptsSuggest fix
Researcher Paul LaRosa reported the critical remote code execution vulnerability.sourcedStory receiptsSuggest fix
AMD took 124 days to fix the flaw.sourcedStory receiptsSuggest fix
AMD refused to pay LaRosa the $10,000 bug bounty despite acknowledging the issue.sourcedStory receiptsSuggest fix
The patched version uses HTTPS but relies on CRC32 validation instead of cryptographic signatures.sourcedStory receiptsSuggest fix
Whether other researchers will disclose similar experiences with AMD's bounty program.developingStory receiptsSuggest fix
Whether AMD has an official bug bounty program or if LaRosa submitted through a third-party platform.sketchyStory receiptsSuggest fix
The exact date LaRosa first reported the vulnerability to AMD.sketchyStory receiptsSuggest fix
Read full story →