#vulnerabilitydisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerabilitydisclosure, aggregated by home.social.
-
Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.
lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.
Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.
-
Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.
lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.
Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.
-
Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.
lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.
Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.
-
Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.
lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.
Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.
-
Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.
lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.
Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.
-
Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.
This week's Policy Pulse: https://blog.disclose.io/policy-pulse-issue-25-week-of-july-18-2026/
-
We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)
Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.
For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.
https://srlabs.de/blog/hacking-ai-agent
#AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure