| |
AMD refused to pay researcher Paul LaRosa a $10,000 bug bounty after he discovered a critical vulnerability in the company's Windows auto-updater that allowed malware injection through unencrypted HTTP connections. The company took 124 days to patch the flaw—far longer than security best practices recommend—and the fix still uses weak CRC32 validation instead of cryptographic signatures, leaving underlying security weaknesses unresolved.
Read Full Article →
← More Tech news