Virtual Event Today: Ransomware Resilience & Recovery Summit - Login to Live Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Intel Patched 226 Vulnerabilities in 2021

Intel patched 226 vulnerabilities in its products last year, according to data from the 2021 Product Security Report released by the chip giant on Thursday.

Intel patched 226 vulnerabilities in its products last year, according to data from the 2021 Product Security Report released by the chip giant on Thursday.

Intel last year said it had paid out an average of $800,000 per year through its bug bounty program since it was launched in 2018, and the company told SecurityWeek this week that the average yearly amount has remained the same, which means payouts should now total more than $3 million.

Of the 226 security holes fixed in 2021, half were discovered internally and 43% were reported through its bug bounty programs — the rest came from open source projects managed by Intel and organizations that cannot seek bug bounties. The number of resolved flaws is roughly the same as in 2019 (236) and 2020 (231).

A majority of the high-severity issues reported through the bug bounty program affected GPUs and processors. As for internally-discovered issues, Ethernet products are at the top.

Vulnerabilities found in Intel products in 2021

Overall, only two vulnerabilities discovered in 2021 were rated “critical” and 52 were rated “high severity” — nearly 150 were classified as “medium severity.”

Intel hosted its bug bounty program on the HackerOne platform until December 2021, when it transitioned to Intigriti. The company is currently offering up to $100,000 for “critical” and “exceptional” vulnerabilities.

Intel this week also announced expanding its bug bounty program with a project named Circuit Breaker, which brings together “elite hackers” to hunt for vulnerabilities in the company’s products. The project involves hosting multiple limited-time events that focus on specific new technologies and platforms.

The first event, which focuses on 11th Gen Core processors, started in December and it will run until May.

Advertisement. Scroll to continue reading.

Related: Intel CPU Vulnerability Can Expose Cryptographic Keys

Related: Intel, AMD Patch High Severity Security Flaws

Related: Intel Releases 29 Advisories to Describe 73 Vulnerabilities Affecting Its Products

Related: Intel Patches Tens of Vulnerabilities in Software, Hardware Products

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.