Intel has suspended its bug bounty program, which previously offered financial rewards for vulnerability disclosures. The program, which launched in 2017 and became open to all researchers in 2018, covered software, hardware, firmware, and open-source projects. Rewards ranged from $500 to $100,000 depending on the quality and severity of the report.
The company has replaced the bounty program with a 'responsible disclosure program without bounties' on the Intigriti platform. No official reason was provided for this change. Intel's website still details the old bounty structure, but the Intigriti site confirms the program's suspension and lack of rewards.
The previous bounty program was a significant source of vulnerability reports for Intel; 105 out of 231 CVEs addressed by Intel in 2020 originated from the program. The removal of financial incentives may reduce the number of external security researchers reporting flaws to Intel, potentially affecting the company's ability to identify and patch vulnerabilities.
This move by Intel follows a trend seen in other projects. The Linux kernel has experienced a significant increase in security reports, with maintainers becoming overwhelmed, partly due to AI-generated reports. Linus Torvalds noted that duplicate AI reports are 'almost entirely unmanageable.' Similarly, Curl closed its bounty program due to a flood of AI-generated submissions. HackerOne's Internet Bug Bounty program also paused submissions, citing the expansion of AI-assisted vulnerability discovery.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Intel has suspended its bug bounty program, which previously offered rewards up to $100,000 per flaw. The company replaced it with a responsible disclosure program on Intigriti that offers no financial rewards, without providing a reason for the change. This shift could reduce external security research contributions, impacting Intel's vulnerability discovery process.