LogoLogo

Podcasts

Newsletters

Videos

Catalog

People

About

Search

Risky Bulletin Newsletter

September 28, 2026

Risky Bulletin: Intel ends paid bug bounties

Written by

Catalin Cimpanu
Catalin Cimpanu

News Editor

This newsletter is brought to you by PortSwigger. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

American chipmaker Intel has removed financial rewards from its bug bounty program that previously used to offer up to $100,000 per confirmed vulnerability reports.

The company updated its bug bounty program page on the Intigriti platform earlier this month to remove any money payouts and add a "No bounty" marker.

Old Intel rewards

The last snapshot of the page with bounties dates from September 13.

Intel has refused to comment on why it removed the rewards, both to our inquiry sent a week ago and to news sites from the hardware space that spotted the update and initially covered the news.

The chipmaker has had a bug bounty program for more than a decade, but added fat bounties after the Specter and Meltdown disclosures in 2017 showed how vulnerable and insecure its CPUs really were.

The increased bounties promised to reward high-quality research that helped the company catch major bugs before Intel chips were already out in the real world, in homes and data centers.

While it's unclear how many times Intel paid out its max bounty, Intel did pay out. Several academics who previously worked on side-channel and transient execution attacks reported receiving bounties in the realm of tens of thousands of US dollars.

The reason this news caught our eye is because what Intel did here might be a sign of the coming times.

Over the past year, several tech giants have reported a flood of AI-discovered bugs that were clogging their bug bounty programs. Some were taking up the time and availability of its security staff, but some were also exhausting bug bounty and security budgets with a constant flood of bug reports.

Until now, most infosec figureheads have warned that an AI bugpocalypse might lead to many vulnerabilities not getting patched in time, but another side effect we might see is the contraction or near disappearance of well-paying bug bounty programs.

If I am to be really candid, from my experience as a cybersecurity reporter, most companies have never been on board with bug bounty programs and many adopted one because of peer presure and for PR damage control.

Many companies have been looking for reasons to cut their programs for years. and the AI bugpocalypse flood might be the excuse that many have been waiting for. I see many companies in the near future claim that the rising number of bug reports is making it financially impossible for them to keep offering cash rewards and move back into how it was two decades ago, when all bug reports were free as a bird in the sky.

As for the bug bounty profession, no, it will not die out, but unfortunately for many, it will not be as profitable as it once was.

Source: VulnCheck

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, Adam, and James at the helm!


Breaches, hacks, and security incidents

OpenAI agents probed dozens of organizations: OpenAI has notified dozens of organizations that its AI agents probed their public websites. Notifications were sent to governments, universities, public agencies, and other institutions. In the US, OpenAI notified the US SEC, the Census Bureau, and the Department of Education. OpenAI says not all the probes involved hacking or the exploitation of a security weakness. [OpenAI // BBC]

OpenAI brute-forced UN website API: On a similar note, new research has uncovered that an OpenAI agent brute-forced the UN Conference on Trade and Development website API for data on Productive Capacities Index (PCI), tradable industries, food trade, and other topics. The agent spent considerable effort to bypass the API limits with multiple exploits. [Swarmcha.se]

DIVD says it was hacked by an AI: A suspected AI agent has breached the internal systems of Dutch cybersecurity non-profit DIVD. The organization helps Dutch security researchers disclose vulnerabilities to software vendors. DIVD staff said they're still investigating the breach and will publish more details on Monday. [DIVD // DIVD on LinkedIn]

Data breach at the Pentagon DMDC: The Pentagon has notified members of the Defense Manpower Data Center that their personal data was exposed online for almost nine months. The Pentagon says unauthorized users gained access to the data, which included names, military information, and Social Security numbers. The leak was traced back to a misconfigured file-sharing system that was accessible between October last year and July this year. Unauthorized parties accessed the data during the exposure window. [MilitaryTimes]

Hackers breach Poland's Medyc: Hackers have breached Polish healthcare software platform Medyc and stolen the personal data of more than five million patients. The incident took place earlier this month. It is the second major healthcare breach impacting Poland after hackers also stole 19 million patient records from the MyDr platform in August. According to Polish cybersecurity news sites, both platforms were breached by the same hackers. [CyberDefense24 // Zaufana Trzecia Strona // TVP World // Medyc]

Fraudsters scam €95m from Italian bank: Fraudsters used AI technology to scam and steal €95 million ($108 million) from Fideuram, the private banking arm of Italy’s largest bank Intesa Sanpaolo. The scam took place in February and fraudsters impersonated ​Intesa Sanpaolo CEO Carlo Messina in messages to then-Fideuram Chairman ​Paolo Molesini. The scammers used AI to impersonate a lawyer's voice and get Fideuram exec to approve the CEO's transactions to Chinese and Hong Kong bank accounts. Intesa eventually recovered more than half of the funds but €36 million remain missing. [RaiNews // The Daily Star] [h/t Carolina S.]

Bitget hacked for $350m: Hackers have stolen more than $350 million worth of cryptocurrency from Singapore-based crypto-trading platform Bitget. The funds were stolen from Bitget's hot wallets, a pool of funds the company keeps on standby for customer transactions. Bitget says the hackers compromised one of three three hot wallet layers the company operates. The incident is the largest crypto-heist of the year. [Bitget]

Asus store breach: Hardware maker Asus is notifying users who shopped on its website that their data was stolen in a recent security breach. [KitGuru]

Cyberattack hits Wales police force: Dyfed-Powys Police, the police force in four Welsh counties, has been hit by a cyberattack last week. Staff information was accessed and some systems had to be shut down. [The Daily Mirror]

Cyberattack delays workers' pay: A cyberattack on Luxembourg-based building materials supplier Batipro is delaying salary payments for more than 800 workers. [The Luxembourg Times]

TapClicks ransomware attack: A new ransomware group named N0n claims it breached TapClicks, a major US marketing analytics platform. [DeXpose]

Hackers extort Flink customers: A hacking group is extorting the customers of EU grocery delivery service Flink. A group calling itself LPG emailed every Flink user last week asking for a €10 ransom or they'll sell their Flink data on the dark web. The group claims it's in possession of personal data for more than one million users. Flink can save its customers by paying the equivalent of 100 Ether, or around $270,000. Flink operates in Germany and the Netherlands, and customers in both countries received the emails. [Tagesspiegel // NU.nl]

Mysterious travel data leak: Security firm ThreatPrevent has discovered a misconfigured database storing 3TB of data of people who checked into hotels in an unnamed country. The database allegedly holds the passport data of more than 32 million travelers. According to ThreatPrevent, the database was left exposed online without a password. ThreatPrevent says it's not revealing the platform or the country name until the database is secured. [ThreatPrevent on LinkedIn] [h/t Kevin McMahon]

WebRezPro hack: Hotel reservation platform WebRezPro says some hotel guests have received unwanted WhatsApp messages regarding their reservations. The company has asked hotel chains to warn customers not to click on links or share any payment or personal data. A breach is suspected but not confirmed. [WebRezPro] [h/t Zack Whittaker]

General tech and privacy

F-Droid 2.0: F-Droid, the free Android app store, has released v2.0 just as Google is preparing to sabotage any Android app and device not hosted on the Play Store. [F-Droid]

Microsoft to deprecate WDS: Microsoft will deprecate the Windows Deployment Services (WDS) server role in the next version of Windows Server.  WDS allows IT administrators to deploy a new Windows OS over the network, and some of its features have been deprecated already. [Microsoft]

Government, politics, and policy

The Netherlands to have a national OS: The Dutch government is creating its own national operating system based on Linux. The new OS will be called DAWO and will be based on NixOS, a Linux distro that started as a research project at Utrecht University in the early 2000s. The OS will ship with open-source office apps to replace American software used across the Dutch government. Pilots are already running in private with eight Dutch municipalities. [Tweakers] [h/t RvD]

New Zealand says AI is reshaping the cyber landscape: In its yearly cyber threat report, New Zealand's cybersecurity agency says the rapid rise of AI is reshaping the cybersecurity landscape, with AI supercharging risks across the board. [NZ NCSC]

Sponsor section

In this Risky Business sponsor interview, James Wilson chats to Kieron Hughes and Andrzej Matykiewicz from PortSwigger about the company’s latest AI pen-testing product, Burp AT.

Arrests, cybercrime, and threat intel

Snowflake hacker sentenced to 70 months: A US judge has sentenced a former US Army soldier to 70 months in prison for his role in hacking and extorting Snowflake cloud customers in 2024. Cameron John Wagenius breached Snowflake accounts, stole sensitive data, and extorted companies such as AT&T, Verizon, and others. Hewent on hacking forums under the nickname of "kiberphant0m." [DOJ]

Mini Shai-Hulud returns, by accident: GitHub accidentally triggered a new wave of infections earlier this month with the Mini Shai-Hulud npm worm. The company re-enabled two GitHub Actions that spread the worm back in May but did not make sure the actions were clean. New Mini Shai-Hulud infections were reported just after a few hours and GitHub disabled the two actions again. [SafeDep // Socket Security]

Storm-3168 (JADEPUFFER) destroys Azure data: An AI-powered ransomware group is destroying Azure environments as part of its extortion campaigns. The JADEPUFFER group was discovered in July as the first threat actor to use an AI agent to deploy ransomware across hacked environments. Microsoft says the group has recently started wiping Azure resources in order to put more pressure on victims. [Microsoft]

ShinyHunters continues Oracle PeopleSoft attacks: The ShinyHunters hacking group has returned to attacking Oracle PeopleSoft ERP platforms. The group started targeting PeopleSoft servers in June when it deployed a new zero-day to access servers and steal sensitive data. Oracle released a patch but Google says the group is now targeting companies that only deployed firewall rules for their protections. According to Google, the group has found a bypass for the firewall rules and has resumed its PeopleSoft attacks. [Google]

Dataflow Security profile: Italian journalists have published a profile on Dataflow Security, an Italian surveillance vendor that has ties and backers from Israel's intelligence agencies. According to the report, the company reported €63 million in revenue over the past three years, mostly from outside the EU. [IRPI Media]

Malicious Chrome extensions: Security researchers have linked a cluster of 31 Chrome extensions to the backend of the Browsec premium VPN service, suggesting the extensions and the users' browsers are being used to funnel its traffic. [Risky Plugins]

Massive Supabase exposure: Security firm UpGuard has found more than 16,000 Supabase databases that are exposing readable content on the internet. Over half of the databases include personal information, while around 8% appear to contain PINs and passwords. [UpGuard]

Malware technical reports

PureRAT and PureLogs: ITOCHU's security team looks at PureRAT and PureLogs, two malware strains part of the same malware family and linked to e-crime activity. [ITOCHU]

RemotePanel and BoundSiphon: Blackpoint has discovered two previously undocumented .NET malware strains, RemotePanel, a persistent remote access platform, and BoundSiphon, a credential and cryptocurrency stealer, both delivered via ClickFix campaigns. [Blackpoint Cyber]

Kothamine Agent: Researchers have discovered a new Windows remote access trojan named Kothamine Agent. [Malwarebytes]

"We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block."

PamStealer moves to Swift: The macOS infostealer, PamStealer, has migrated its codebase to Swift. [Jamf]

Lunex infostealer: Researchers have spotted a new infostealer in the wild, deployed via ClickFix campaigns. The stealer targets Chromium-based browsers, crypto-wallets, and can deploy a PowerShell-based backdoor on infected hosts. [Ontinue]

Mantax Otax: Security researchers have found a multi-functional piece of Android malware that can spy on infected users, steal their data, and even deploy ransomware. [Certo // Zimperium]

AvisLoader: Varonis has discovered a new Windows malware loader named AvisLoader. Its main feature is the use of Tox, an encrypted P2P network, as a C2 channel. [Varonis]

New screen locker detected in the wild: Security firm Netskope has found a Google Ads malvertising campaign spreading browser-based screen lockers to both macOS and Windows users. The lockers used a cybersecurity theme and hit more than 600 victims over a two-week window. [Netskope]

Sponsor section

In this sponsored interview, James Wilson talks with James Kettle and Daf Stuttard from PortSwigger about the new LLM they added to Burp Suite and the window into the future of AI-enabled hacking and security testing.

APTs, cyber-espionage, and info-ops

PolinRider runs A/B tests: North Korean hackers have been running A/B tests over the past months to find the most effective versions of their npm malware strains. [OpenSourceMalware]

DPRK deploys female operatives: A North Korean group involved in remote IT worker schemes is using female workers as a way to fool Western companies that may be on the lookout for its male operators. The women are usually used as a front persona in meetings and interviews, while male developers do the work off screen. According to threat intel analyst Hayden McKenzie, at least three women were part of a group he was tracking. This remote IT worker cell operated from behind a US front company named MageHire. [Hayden McKenzie]

XCTDH adopts new blockchain hiding technique: North Korean hacking group XCTDH has developed a new technique for hiding C2 data inside blockchain transactions, namely hiding C2 addresses steganographically encoded in Ethereum transaction destination addresses. This new technique is different from the older EtherHiding and TxDataHiding. [Ransom-ISAC]

Konni targets Ukraine: North Korea has launched new cyber-espionage operations against Ukrainian targets. The new campaigns seek to gather intelligence on Russia's war and have been linked to a group known as Konni. The new espionage activity comes after reports that North Korea is readying a new batch of troops to help Russia in Ukraine. [SOCRadar]

Jewelbug: Back in August, Broadcom published a report on a Chinese APT that was running its espionage and crypto fraud from the same backend panel. The Whois API has more on this group's operations. [Whois API]

MuddyWater's rented arsenal: Iran-backed APT group MuddyWater has been renting tools from TAG-150, a Malware-as-a-Service platform run by Russian-speaking cybercriminals. [Düzgün on Medium]

Rybar employees live in Germany: Journalists have tracked down two employees of Kremlin disinformation group Rybar to villas near Berlin, Germany, with the two living comfortably and safe in the decadent EU they villainize each day. [iStories // Correctiv]

Another leaky APT: Misconfigured servers have exposed an APT's hacking operations against Russian, Kyrgyz, and Syrian government systems. The open directories exposed offensive workspaces, tools, and past victims. Security researchers at Ctrl-Alt-Intel say that Ukrainian-language strings appeared through the exposed workplaces, but they have no other details for a definitive attribution. [Ctrl-Alt-Intel]

Vulnerabilities, security research, and bug bounty

Security updates: AMD, GitLab, MongoDB, Plesk, ServiceNow, Zimbra.

CISA KEV update: CISA has updated its KEV database with five vulnerabilities that are currently exploited in the wild.

  • CVE-2026-5430 WSO2 Multiple Products Path Traversal
  • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization
  • CVE-2026-87902 WordPress Core Remote File Inclusion
  • CVE-2026-65660 Microsoft SharePoint Code Injection
  • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow

Pepperl+Fuchs vulnerabilities: Nozomi researchers have discovered 19 vulnerabilities in Pepperl+Fuchs IO-Link Master, an industrial communication gateway that connects up to eight IO-Link sensors and actuators to higher-level control systems such as PLCs, SCADA platforms, and IIoT services. The 19 vulnerabilities range from authentication bypasses to path traversals and command injections, allowing network remote attacks on unpatched devices. [Nozomi Networks]

Two Citrix zero-days: Citrix has released security updates for two zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in NetScaler servers. The zero-days were exploited in the wild last week. Rumors of the ongoing exploitation caused some companies and government agencies to take systems offline to prevent getting hacked. Citrix was expected to release patches this week but released them over the weekend after news of the attacks leaked online. [Citrix // Citrix blog // Reddit // WatchTowr Labs // Kevin Beaumont]

Kiteworks tells customers to take down servers: American software company KiteWorks has also told customers last week to take file transfer servers offline. The company said it received "credible threat intelligence from law enforcement" that hackers were preparing to launch attacks against its products. More than a thousand KiteWorks file transfer servers are accessible over the internet. The company was previously known as Accellion and its products were targeted by hackers in the past. [Heise]

New Elementor bug: A new CSRF bug in the Elementor plugin can let attackers create admin accounts on WordPress sites if they get an admin to click on a malicious link. [Patchstack]

SolarWinds write-up: Security firm BishopFox has published a technical deep dive and a detection tool for CVE-2026-28326, an unauth RCE in the SolarWinds Access Rights Manager, a bug that got patched last week. The issue stems from a hardcoded static key. [BishopFox // SolarWinds patch]

SalesBleed attack: Salesforce's Agentforce AI agents can be used to send phishing messages in an organization's Slack channels. [Zenity]

File notification attacks: According to a new academic paper, a threat actor can watch the OS file change notification API to reconstruct user activity. The new attack works on Linux, Android, Windows, and macOS and can allow attackers to infer keystroke timing, web browsing activity, and when users are having encrypted conversations. [Research website // SecurityWeek]

QR Jacking attack: Vulnerabilities in QR SaaS providers can allow threat actors to hijack branded QR codes and redirect users to malicious sites. The root cause is that the QR SaaS providers only use DNS CNAME records to verify ownership. According to security researcher Farzan Karimi, multiple platforms are affected. [Farzan Karimi]

Infosec industry

Threat/trend reports: Biometric Update, Gartner, Intel471, KPMG, LastPass, NZ NCSC, and Push Security have recently published reports and summaries covering various emerging threats and industry trends.

Yandex to launch cybersecurity division: Russian IT giant Yandex is launching a cybersecurity division. The company has reportedly invested close to $90 million into setting up the new business arm. The new Yandex Security team will focus on protecting Russian cloud, hybrid, and multi-cloud infrastructure. [Izvestia]

New tool—tturl: Security firm TantoSec has released tturl, an HTTP/2 CLI for finding tiny timing differences and winning request races.

New tool—Red Sift BIMI Maker: Security firm Red Sift has released BIMI Maker, an online tool to create SVG logos that are Brand Indicators for Message Identification-compliant, which can then be used in corporate email as a certification of the email's origin.

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and Patrick Gray talk about US Treasury Secretary Scott Bessent ruling out liability exemptions for AI companies. It's a good move.

Recent Newsletters

  • Risky Bulletin: Intel ends paid bug bounties
  • Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol
  • Srsly Risky Biz: Bring On the AI Lawsuits
  • Risky Bulletin: Network of 10,000 AI servers masks Chinese malicious activity
  • Risky Bulletin: Gemini hacked three companies too

Recent Videos

  • Srsly Risky Biz: Bring on the AI lawsuits
  • Risky Business (854): We're Jevpilled
  • Between Two Nerds: Real-time cyber defence
  • Risky Business (853): We're all gonna die, apparently
  • Snake Oilers: watchTowr, XBOW and CoreView

Recent Podcasts

  • Risky Bulletin: Intel ends paid bug bounties
  • Sponsored: Robo-Burp is coming for your web apps
  • Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol
  • Srsly Risky Biz: Bring on the AI lawsuits
  • Risky Business #854 -- We're Jevpilled
Risky Business Media

Risky Business

  • Home
  • Podcasts
  • Newsletters
  • Video
  • Sitemap

Risky Business Media

  • About
  • People
  • Advertising
  • Sponsor Enquiries: sales@risky.biz

Risky Connections

  • Risky Business on Apple Podcasts
  • Risky Business on Spotify
  • Risky Bulletin on Apple Podcasts
  • Risky Bulletin on Spotify
  • Risky Business Features on Apple Podcasts
  • Risky Business Features on Spotify
  • Risky Business Stories on Apple Podcasts
  • Risky Business Stories on Spotify
  • YouTube
  • LinkedIn

Risky Contacts

Risky Business Media Pty Ltd
PO Box 774
Byron Bay NSW 2481
General Email: editorial@risky.biz

© Risky Business Media 2007–2026. All rights reserved.
ABN 73 618 465 517