Intel has suspended its paid vulnerability-reward program on Intigriti, which had accepted findings affecting its hardware, software, firmware, open-source projects, and later web services. The program offered rewards ranging from $500 to $100,000; its public bounty page remains online but is marked as suspended.
Researchers may still report vulnerabilities through a replacement responsible-disclosure program on Intigriti, but the new process provides no monetary rewards. Intel has not publicly explained the change. While AI-generated and duplicate reports have burdened disclosure programs elsewhere, there is no evidence that they caused Intel's decision; an earlier Intigriti update said the company was evaluating enhanced bounty and bonus criteria.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Intel launched an Intigriti responsible-disclosure program through which researchers can continue submitting vulnerability reports, but the replacement program provides no monetary bounties.
Intel suspended its Intigriti-hosted paid bug bounty program, whose awards had ranged from $500 to $100,000 and covered hardware, software, firmware, and open-source projects. The bounty board remained accessible but was marked as suspended, and Intel gave no public explanation for ending paid rewards.
Intel expanded its bounty program's eligible scope to include web services during the period from mid-2025 through October 2025.
Intel said that 105 of the 231 CVEs it addressed during 2020 had been submitted through its bug bounty program.
Intel expanded access to its bug bounty program, opening submissions to all researchers.
Intel launched its bug bounty program as an invite-only initiative for security researchers.
In an Intigriti update, Intel said it was evaluating enhanced bounty and bonus criteria.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.