FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity

A Critical Flaw AMD Said Was Not Their Problem

A software developer sits at a desk with a laptop and second monitor, focused on the code displayed on the screen.
AMD logo
AMD news →

TL;DR: A security researcher found a critical vulnerability on an official AMD website. AMD dismissed the report without a reward, stating the third-party software was out of scope, raising questions about corporate security responsibility.

By Neeraj Dhiman·3h ago·2 min read·updated 1h ago
Source

Key facts

Category
Cybersecurity
Impact
Low
Published
3h ago
Source
Hacker News

Full summary

A researcher found a critical flaw on an AMD website. AMD called it "out of scope" and refused to pay a bounty.

A security researcher discovered a severe Remote Code Execution (RCE) vulnerability on an official AMD subdomain. The flaw was not in an AMD product but in an outdated version of vBulletin, a third-party forum software powering the company's community site. RCEs are among the most serious security risks, as they can allow an attacker to run their own code on a target server. The researcher responsibly disclosed the issue through AMD's bug bounty program on HackerOne, expecting a reward and a swift fix for the high-impact finding.

Instead of a reward, AMD’s security team closed the report as "Informative" and "Out of Scope." Their reasoning was that the bug bounty program only covers AMD-developed products, not third-party applications running on their infrastructure. While AMD did eventually take the vulnerable website offline, the company did not pay a bounty or formally acknowledge the report's severity. This response has sparked a debate about corporate responsibility for the security of an entire digital footprint. For security teams, it’s a reminder that attackers do not care about internal policies; a vulnerability on a trusted domain is a threat that can be used for phishing or spreading malware, regardless of its source.

The incident serves as a case study on the potential pitfalls of narrowly defined bug bounty programs. When scopes are too rigid, companies risk demotivating researchers from reporting valid threats on their attack surface. It highlights the critical need for organizations to have a clear policy for handling all vulnerability disclosures, not just those that fit neatly into a bounty structure. For businesses, this underscores the importance of continuously auditing all assets, including third-party software, and fostering a positive relationship with the security research community.

Why it matters

Highlights the risks of narrowly-scoped bug bounty programs and the importance of securing all company web assets, including those running third-party software. An RCE on a trusted domain is a major threat, regardless of its origin.

Business impact

This incident can damage a company's reputation with the security research community, potentially discouraging future disclosures. It also underscores the legal and brand risk of vulnerabilities on any official domain, which can be exploited for phishing or malware distribution, eroding customer trust.

Tags

#security#vulnerability#rce#bug-bounty#amd#hackerone

Related on Notifire

  • ResearchCritical CVEs of 2026
  • ResearchKubernetes security
  • GlossaryCVE
  • ResearchSupply-chain security

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: Hacker News

Part of our research on

  • Critical CVEs of 2026 →

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube