← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Intel suspends bug bounty program, replaces it with unrewarded disclosure program

🔄 Updated 4d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Intel suspended its bug bounty program.
  • The new program on Intigriti offers no rewards.
  • The previous program paid up to $100,000 per bug.
  • 105 of 231 CVEs in 2020 came from the bounty program.

Intel's Bug Bounty Program Suspended

Intel has suspended its bug bounty program, which previously offered financial rewards for vulnerability disclosures. The program, which launched in 2017 and became open to all researchers in 2018, covered software, hardware, firmware, and open-source projects. Rewards ranged from $500 to $100,000 depending on the quality and severity of the report.

Replacement Program Offers No Rewards

The company has replaced the bounty program with a 'responsible disclosure program without bounties' on the Intigriti platform. No official reason was provided for this change. Intel's website still details the old bounty structure, but the Intigriti site confirms the program's suspension and lack of rewards.

Impact on Vulnerability Discovery

The previous bounty program was a significant source of vulnerability reports for Intel; 105 out of 231 CVEs addressed by Intel in 2020 originated from the program. The removal of financial incentives may reduce the number of external security researchers reporting flaws to Intel, potentially affecting the company's ability to identify and patch vulnerabilities.

Industry Context

This move by Intel follows a trend seen in other projects. The Linux kernel has experienced a significant increase in security reports, with maintainers becoming overwhelmed, partly due to AI-generated reports. Linus Torvalds noted that duplicate AI reports are 'almost entirely unmanageable.' Similarly, Curl closed its bounty program due to a flood of AI-generated submissions. HackerOne's Internet Bug Bounty program also paused submissions, citing the expansion of AI-assisted vulnerability discovery.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Intel has suspended its bug bounty program, which previously offered rewards up to $100,000 per flaw. The company replaced it with a responsible disclosure program on Intigriti that offers no financial rewards, without providing a reason for the change. This shift could reduce external security research contributions, impacting Intel's vulnerability discovery process.