home.social

#vulnerabilitydisclosure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulnerabilitydisclosure, aggregated by home.social.

  1. Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.

    lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.

    Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.

    lookup.disclose.io

    #VulnerabilityDisclosure

  2. lookup.disclose.io runs inside the tools you already use, thin clients over one API:

    dio-lookup CLI (npm), Caido plugin, Burp and ZAP extensions, Chrome extension, Nmap NSE, Nuclei templates, a hosted MCP server in the MCP registry, and a JSON API with OpenAPI 3.1 and llms.txt.

    Since August 13 the Burp, ZAP, Caido, and Chrome plugins are route-aware: contacts grouped the way the site groups them, owner route first.

    github.com/disclose

    #VulnerabilityDisclosure #AppSec