#vulnerabilitydisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerabilitydisclosure, aggregated by home.social.
-
Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.
This week's Policy Pulse: https://blog.disclose.io/policy-pulse-issue-25-week-of-july-18-2026/
-
Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.
The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.
-
Two new ways to find the right disclosure contact from your tooling:
🔌 Disclosure Lookup is now in the official #Caido plugin store — right-click a request, get the verified security contact for that host.
📦 dio-lookup is live on npm — pipe-friendly CLI: subfinder | httpx | dio-lookupFree + MIT-licensed, powered by https://lookup.disclose.io — Burp + Chrome extensions are in store review.
Flag anything wrong — feedback feeds our accuracy audit.
-
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
https://winbuzzer.com/2026/04/09/windows-zero-day-published-on-github-after-msrc-silence-xcxwbn/
Windows Zero-Day Published on Github as Microsoft Fails to Act
#Microsoft #Windows #WindowsSecurity #Cybersecurity #ZeroDayVulnerabilities #Exploits #Vulnerability #VulnerabilityDisclosure #SecurityResearch #Windows11 #BigTech
-
We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)
Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.
For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.
https://srlabs.de/blog/hacking-ai-agent
#AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure
-
Acknowledging Reality in Vulnerability Disclosure.
Every few years, vulnerability disclosure is declared settled. We are told that the ecosystem has matured, that coordinated disclosure is the answer, and that whatever remains outside this model is either irresponsible, obsolete, or simply irrelevant.
🔗 https://www.foo.be/2026/02/Acknowledging-Reality-in-Vulnerability-Disclosure
#vulnerabilitymanagement #gcve #cve #cybersecurity #cvd #vulnerabilitydisclosure #open
This is my bloody personal blog, not an official statement. .
-
Check out ˗ˏˋ ⭒ https://lnkd.in/gE2wUqgc ⭒ ˎˊ˗ to see my intro whilst you listen.
I'm thus re-naming this work as "CVE Keeper - Security at x+1; rethinking vulnerability management beyond CVSS & scanners". I must also thank @andrewpollock for reviewing several of my verbose drafts. 🫡
So, Security at x+1; rethinking vulnerability management beyond CVSS & scanners -
Most vulnerability tooling today is optimized for disclosure and alert volume, not for making correct decisions on real systems. CVEs arrive faster than teams can evaluate them, scores are generic, context arrives late, and we still struggle to answer the only question that matters: does this actually put my system at risk right now?
Over the last few years working close to CVE lifecycle automation, I’ve been designing an open architecture that treats vulnerability management as a continuous, system-specific reasoning problem rather than a static scoring task. The goal is to assess impact on the same day for 0-days using minimal upstream data, refine accuracy over time as context improves, reason across dependencies and compound vulnerabilities, and couple automation with explicit human verification instead of replacing it.
This work explores:
⤇ 1• Same-day triage of newly disclosed and 0-day vulnerabilities
⤇ 2• Dependency-aware and compound vulnerability impact assessment
⤇ 3• Correlating classical CVSS with AI-specific threat vectors
⤇ 4• Reducing operational noise, unnecessary reboots, and security burnout
⤇ 5• Making high-quality vulnerability intelligence accessible beyond enterprise teamsThe core belief is simple: most security failures come from misjudged impact, not missed vulnerabilities. Accuracy, context, and accountability matter more than volume.
I’m sharing this to invite feedback from folks working in CVE, OSV, vulnerability disclosure, AI security, infra, and systems research. Disagreement and critique are welcome. This problem affects everyone, and I don’t think incremental tooling alone will solve it.
P.S.
- Super appreciate everyone that's spent time reviewing my drafts and reading all my essays lol. I owe you 🫶🏻
- ... and GoogleLM. These slides would have taken me forever to make otherwise.
Take my CVE-data User Survey to allow me to tailor your needs into my design - lnkd.in/gcyvnZeE
See more at - lnkd.in/gGWQfBW5
lnkd.in/gE2wUqgc#VulnerabilityManagement #Risk #ThreatModeling #CVE #CyberSecurity #Infosec #VulnerabilityManagement #ThreatIntelligence #ApplicationSecurity #SecurityOperations #ZeroDay #RiskManagement #DevSecOps #CVE #CVEAnalysis #VulnerabilityDisclosure #SecurityData #CVSS #VulnerabilityAssessment #PatchManagement #AI #AIML #AISecurity #MachineLearning #AIThreats #AIinSecurity #SecureAI #OSS #Rust #ZeroTrust #Security
https://www.linkedin.com/feed/update/urn:li:activity:7409399623087370240
-
Why vulnerability reports stall inside shared hosting companies https://www.helpnetsecurity.com/2025/12/17/hosting-provider-vulnerability-notifications-remediation/ #vulnerabilitydisclosure #vulnerabilitymanagement #cybersecurity #Don'tmiss #Features #Hotstuff #research #strategy #News #tips
-
OIG Audit Finds Commerce Department Failing to Fully Secure Public-Facing Systems https://thecyberexpress.com/vdp-oig-audit-cybersecurity/ #VulnerabilityDisclosure #TheCyberExpressNews #Vulnerabilities #TheCyberExpress #FirewallDaily #CyberNews #CISA #OIG #VDP
-
A 21-year-old cybersecurity entrepreneur in Russia has been arrested on treason charges, reportedly after publicly criticizing the Max messaging platform and raising concerns about new anti-cybercrime legislation.
With the case classified, details remain unclear - but the situation underscores the challenges faced by researchers operating in tightly regulated environments.
💬 What protections should security researchers have?
Follow @technadu for continuous global InfoSec coverage.#InfoSec #Cybersecurity #DigitalRights #SecurityResearch #VulnerabilityDisclosure #TechNews
-
What happens when vulnerability scores fall apart? https://www.helpnetsecurity.com/2025/11/24/sonatype-vulnerability-scoring-gaps-report/ #vulnerabilitydisclosure #softwaredevelopment #cybersecurity #opensource #Sonatype #report #News #risk #CVE
-
Testing out the new author attribution feature: https://skyplabs.com/posts/xss-iban-secured-transfer/
#Security #Web #WebSecurity #XSS #VulnerabilityDisclosure #Notary #Mastodon #Fediverse
-
When two firms uncover the same flaw, who really deserves the credit? A battle between FuzzingLabs and Gecko Security is shaking up CVE attribution—and it might change the game for cybersecurity. Read the full story.
#vulnerabilitydisclosure
#cvecredit
#cybersecurityethics
#infosec
#securityresearch -
How to get better results from bug bounty programs without wasting money https://www.helpnetsecurity.com/2025/10/07/bug-bounty-rewards-better-results/ #vulnerabilitydisclosure #AltaAssociates #cybersecurity #Don'tmiss #bugbounty #Intigriti #Features #Hotstuff #strategy #UpCloud #Google #News #CISO #tips
-
Ruckus network management solutions riddled with unpatched vulnerabilities https://www.helpnetsecurity.com/2025/07/10/ruckus-network-management-solutions-riddled-with-unpatched-vulnerabilities/ #CarnegieMellonUniversity #vulnerabilitydisclosure #RuckusNetworks #vulnerability #networking #Don'tmiss #Hotstuff #wireless #Claroty #News
-
CISA: Recently fixed Chrome vulnerability exploited in the wild (CVE-2025-4664) https://www.helpnetsecurity.com/2025/05/16/cisa-recently-fixed-chrome-vulnerability-exploited-in-the-wild-cve-2025-4664/ #vulnerabilitydisclosure #securityupdate #MicrosoftEdge #vulnerability #Don'tmiss #Hotstuff #Chrome #Google #News #CISA
-
@sergedroz @gcve Hello, thank you for your question.
Both OVR and GCVE share the same goal: strengthening global vulnerability coordination.
However, from what I understand, GCVE is still based on individual instances that could fail without true redundancy.
Additionally, GCVE is maybe not really neutral due to its structure and affiliations.OVR is developing a fully decentralized and resilient concept — not just for vulnerabilities, but also preparing for SBOM integration and considering upcoming legal requirements (e.g., cybersecurity regulations).
Our vision is an open, neutral, and community-based ecosystem that can survive political risks, technical outages, and grow sustainably with the global community.
Further information will follow in the next few days.
#CyberSecurity #VulnerabilityDisclosure #Decentralization #SBOM #OpenStandards #OVRFoundation #Resilience #DigitalSecurity
#CVE #OVR #GCVE #security #it #community -
Funding uncertainty may spell the end of MITRE’s CVE program https://www.helpnetsecurity.com/2025/04/16/funding-uncertainty-may-spell-the-end-of-mitres-cve-program/ #vulnerabilitydisclosure #vulnerabilitymanagement #CardinalOps #Don'tmiss #VulnCheck #Hotstuff #Edera #MITRE #News #CVE
-
Microsoft DRM Hacking Raises Questions on Vulnerability Disclosures – Source: www.securityweek.com https://ciso2ciso.com/microsoft-drm-hacking-raises-questions-on-vulnerability-disclosures-source-www-securityweek-com/ #rssfeedpostgeneratorecho #vulnerabilitydisclosure #CyberSecurityNews #bugbountyprogram #vulnerabilities #securityweekcom #Dataprotection #securityweek #controversy #Microsoft #PlayReady #FEATURED
-
Microsoft DRM Hacking Raises Questions on Vulnerability Disclosures https://www.securityweek.com/microsoft-drm-hacking-raises-questions-on-vulnerability-disclosures/ #vulnerabilitydisclosure #bugbountyprogram #Vulnerabilities #DataProtection #controversy #Microsoft #PlayReady #Featured
-
Microsoft DRM Hacking Raises Questions on Vulnerability Disclosures https://www.securityweek.com/microsoft-drm-hacking-raises-questions-on-vulnerability-disclosures/ #vulnerabilitydisclosure #bugbountyprogram #Vulnerabilities #DataProtection #controversy #Microsoft #PlayReady #Featured
-
Hackers Can Be Heroes: The Importance of Responsible Disclosure https://thecyberexpress.com/cybersecurity-importance-disclosure/ #collaborationincybersecurity #SeeSomethingSaySomething #VulnerabilityDisclosure #VulnerabilityReporting #TheCyberExpressNews #Vulnerabilities #TheCyberExpress #securitybreach #FirewallDaily #CyberNews #CISA
-
Vulnerability advisory🚨
Local file inclusion identified in Milesight DeviceHub
Our Joe Lovett discovered a flaw within the nginx docker container, enabling unauthenticated access to sensitive MQTT certificates, including private keys.
See more on our website:
🔗 https://www.pentestpartners.com/security-blog/unauthenticated-local-file-disclosure-on-milesight-devicehub/#CyberSecurity #VulnerabilityResearch #Milesight #LocalFileInclusion #CyberThreats #VulnerabilityDisclosure #SecurityAdvisory
-
EU adopts Cyber Resilience Act to secure connected products – Source: www.helpnetsecurity.com https://ciso2ciso.com/eu-adopts-cyber-resilience-act-to-secure-connected-products-source-www-helpnetsecurity-com/ #rssfeedpostgeneratorecho #vulnerabilitydisclosure #VulnerabilityManagement #CyberSecurityNews #HELPNETSECURITY #helpnetsecurity #enterprise #opensource #regulation #Smarthome #Dontmiss #Hotstuff #News #SMBs #IoT #EU