home.social

#vulndisclosure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulndisclosure, aggregated by home.social.

fetched live
  1. Safe harbor makes it safe to report a vulnerability. The other half, talked about far less: report well.

    We've cross-posted Daniel Stenberg's (curl) guide to writing vulnerability reports that actually get fixed — with our own commentary on why report quality protects maintainers the way safe harbor protects researchers.

    blog.disclose.io/what-makes-a-

    #infosec #vulndisclosure

  2. Safe harbor makes it safe to report a vulnerability. The other half, talked about far less: report well.

    We've cross-posted Daniel Stenberg's (curl) guide to writing vulnerability reports that actually get fixed — with our own commentary on why report quality protects maintainers the way safe harbor protects researchers.

    blog.disclose.io/what-makes-a-

    #infosec #vulndisclosure

  3. New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
    blog.disclose.io/above-the-par
    #infosec #CFAA #vulndisclosure

  4. New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
    blog.disclose.io/above-the-par
    #infosec #CFAA #vulndisclosure

  5. New methodology paper: The Calculator Discipline.

    A four-class taxonomy of AI-assisted disclosure hallucinations, a pre-send filter that catches the mechanical ones, and two real withdrawals from my own OpenBSD work — including the one Theo de Raadt asked the right question about.

    Honest case studies from the sender's end of a problem the field has only described from the receiving end.

    CC BY 4.0 · BSD-2-Clause tool.

    stuart-thomas.com/research/cal

    #infosec #OpenBSD #AI #vulndisclosure #methodology

  6. Portugal’s cybercrime law now exempts security researchers from prosecution for good-faith research. HIGH severity (regulatory), not a technical threat. No CVE, but likely more vulnerability disclosures from Portugal ahead. radar.offseq.com/threat/portug #OffSeq #CyberLaw #VulnDisclosure

  7. NVD Delays Leave Defenders in the Dark — Early Visibility is Key
    Tenable’s recent analysis shows a worrying pattern in vulnerability disclosure timing:
    - 63,862 CVEs from 2024–2025
    - 56% of PoCs released within 7 days
    - NVD lagging by ~15 days
    - Exploitation confirmed in as little as 5 days
    This gap between CVE assignment, PoC publication, and NVD visibility creates exploitable blind spots for enterprises relying on traditional patch cycles.
    💬 Security leaders - how do you bridge these gaps? Do you trust vendor advisories, exploit feeds, or telemetry-driven signals more?

    👍 Like and follow @technadu for continuous coverage of emerging vulnerability management insights.

    #InfoSec #CyberSecurity #VulnerabilityManagement #ThreatIntel #NVD #Exploit #RiskIntel #Tenable #CVEs #CyberDefense #ZeroDay #CVETracking #VulnDisclosure #TechNadu