AMD disclosed vulnerabilities affecting a broad range of processor, graphics, and accelerator products, including EPYC, Ryzen, Athlon, Threadripper, Instinct MI300A, and Radeon PRO V620 lines. The issues are tracked through AMD’s processor-vulnerability security resources, including bulletin AMD-SB-7009; public advisories did not specify vulnerability types, exploit conditions, or evidence of active exploitation.
Organizations should inventory affected AMD-based servers, desktops, mobile systems, embedded devices, workstations, and accelerators, then obtain and deploy the applicable platform-initialization (PI) firmware updates from their OEM or AMD. Administrators should verify that deployed firmware meets AMD’s published minimum non-affected versions; Radeon PRO V620 customers should contact AMD Customer Engineering for remediation guidance.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-879 covering the affected AMD products and advised users and administrators to review AMD security information and apply required firmware or platform updates as they become available.
Multiple AMD processor and graphics product families, including EPYC, Ryzen, Athlon, Threadripper, Instinct MI300A, and Radeon PRO V620 products, were identified as affected by unspecified vulnerabilities. Minimum Platform Initialization firmware versions were listed as remediations for most affected families, while Radeon PRO V620 customers were directed to AMD Customer Engineering.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourceamd.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.