#vulndisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulndisclosure, aggregated by home.social.
-
Safe harbor makes it safe to report a vulnerability. The other half, talked about far less: report well.
We've cross-posted Daniel Stenberg's (curl) guide to writing vulnerability reports that actually get fixed — with our own commentary on why report quality protects maintainers the way safe harbor protects researchers.
https://blog.disclose.io/what-makes-a-vulnerability-report-excellent/
-
Safe harbor makes it safe to report a vulnerability. The other half, talked about far less: report well.
We've cross-posted Daniel Stenberg's (curl) guide to writing vulnerability reports that actually get fixed — with our own commentary on why report quality protects maintainers the way safe harbor protects researchers.
https://blog.disclose.io/what-makes-a-vulnerability-report-excellent/
-
New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
#infosec #CFAA #vulndisclosure -
New: "Sticking their heads out above the parapets" — the first qualitative study of researchers' lived experiences of legal risk, by Sunoo Park & Daniel R. Thomas (USENIX Security 2026). 36 researchers, 130 incidents, three decades. The CFAA and UK Computer Misuse Act chill good-faith research; it names disclose.io as part of the fix. Read it + catch the talk:
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
#infosec #CFAA #vulndisclosure -
New methodology paper: The Calculator Discipline.
A four-class taxonomy of AI-assisted disclosure hallucinations, a pre-send filter that catches the mechanical ones, and two real withdrawals from my own OpenBSD work — including the one Theo de Raadt asked the right question about.
Honest case studies from the sender's end of a problem the field has only described from the receiving end.
CC BY 4.0 · BSD-2-Clause tool.
-
Portugal’s cybercrime law now exempts security researchers from prosecution for good-faith research. HIGH severity (regulatory), not a technical threat. No CVE, but likely more vulnerability disclosures from Portugal ahead. https://radar.offseq.com/threat/portugal-updates-cybercrime-law-to-exempt-security-e1a7abd5 #OffSeq #CyberLaw #VulnDisclosure
-
NVD Delays Leave Defenders in the Dark — Early Visibility is Key
Tenable’s recent analysis shows a worrying pattern in vulnerability disclosure timing:
- 63,862 CVEs from 2024–2025
- 56% of PoCs released within 7 days
- NVD lagging by ~15 days
- Exploitation confirmed in as little as 5 days
This gap between CVE assignment, PoC publication, and NVD visibility creates exploitable blind spots for enterprises relying on traditional patch cycles.
💬 Security leaders - how do you bridge these gaps? Do you trust vendor advisories, exploit feeds, or telemetry-driven signals more?👍 Like and follow @technadu for continuous coverage of emerging vulnerability management insights.
#InfoSec #CyberSecurity #VulnerabilityManagement #ThreatIntel #NVD #Exploit #RiskIntel #Tenable #CVEs #CyberDefense #ZeroDay #CVETracking #VulnDisclosure #TechNadu