THE CRUNCH
Intel has paused its lucrative bug bounty programme that once paid up to $100,000 per flaw. The replacement Intigriti programme offers no rewards. The company’s site still lists the old programme, which launched in 2017 and covered software, hardware and firmware, but the bounty board now shows it as suspended. Almost half of the CVEs Intel addressed in 2020 arrived through the bounty programme. Researchers can still
submit vulnerabilities through the new programme, but they will not receive a reward. The move follows a dispute over scope with a bounty hunter in June. Tom's Hardware speculates that the flood of AI-generated reports on projects like the Linux kernel may have played a role, noting that AI tools have already caused other programmes to close. HackerOne’s Internet Bug Bounty programme also paused submissions in March, citing AI-assisted research.


