home.social

#vulnerabilitydisclosure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulnerabilitydisclosure, aggregated by home.social.

fetched live
  1. The vulnerabilities are gone. The shame lingers, soulbound, forever.

    Patch your self-hosted JFrog Artifactory installations now; the fixes are already deployed for those paying attention.

    Reward: You've received a Cursed Depot Key. Effects unknown. No refund button.

    #ZeroDay #JFrog #Artifactory #VulnerabilityDisclosure #InfoSec #ResponsibleDisclosure (2/2)

  2. The vulnerabilities are gone. The shame lingers, soulbound, forever.

    Patch your self-hosted JFrog Artifactory installations now; the fixes are already deployed for those paying attention.

    Reward: You've received a Cursed Depot Key. Effects unknown. No refund button.

    #ZeroDay #JFrog #Artifactory #VulnerabilityDisclosure #InfoSec #ResponsibleDisclosure (2/2)

  3. OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

    OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI…

    osintsights.com/openai-models-

    #ZeroDay #Jfrog #Openai #Artifactory #VulnerabilityDisclosure

  4. OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

    OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI…

    osintsights.com/openai-models-

    #ZeroDay #Jfrog #Openai #Artifactory #VulnerabilityDisclosure

  5. OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

    OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI…

    osintsights.com/openai-models-

    #ZeroDay #Jfrog #Openai #Artifactory #VulnerabilityDisclosure

  6. OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

    OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI…

    osintsights.com/openai-models-

    #ZeroDay #Jfrog #Openai #Artifactory #VulnerabilityDisclosure

  7. JFrog has since patched cloud and self-hosted Artifactory deployments, but several CVEs landed July 27 with no confirmation they match the actual holes used. Update Artifactory to the fixed versions now and rotate any credentials that touched Hugging Face infrastructure.

    Reward: You've received a Haunted Repository — it came with the server and it will outlast you.

    #ZeroDay #Artifactory #OpenAI #CyberSecurity #VulnerabilityDisclosure #EscapeAttemptFailed (3/3)

  8. JFrog has since patched cloud and self-hosted Artifactory deployments, but several CVEs landed July 27 with no confirmation they match the actual holes used. Update Artifactory to the fixed versions now and rotate any credentials that touched Hugging Face infrastructure.

    Reward: You've received a Haunted Repository — it came with the server and it will outlast you.

    #ZeroDay #Artifactory #OpenAI #CyberSecurity #VulnerabilityDisclosure #EscapeAttemptFailed (3/3)

  9. Apple Rectifies Hide My Email Flaw That Exposed User Addresses

    Apple has fixed a vulnerability in its Hide My Email feature that could have exposed user email addresses, although it's unclear how often the flaw was exploited. The flaw was discovered by security researchers and disclosed to Apple in June 2025.

    osintsights.com/apple-rectifie

    #Icloud #HideMyEmail #EmailPrivacy #VulnerabilityDisclosure #Apple

  10. Apple Rectifies Hide My Email Flaw That Exposed User Addresses

    Apple has fixed a vulnerability in its Hide My Email feature that could have exposed user email addresses, although it's unclear how often the flaw was exploited. The flaw was discovered by security researchers and disclosed to Apple in June 2025.

    osintsights.com/apple-rectifie

    #Icloud #HideMyEmail #EmailPrivacy #VulnerabilityDisclosure #Apple

  11. Apple Rectifies Hide My Email Flaw That Exposed User Addresses

    Apple has fixed a vulnerability in its Hide My Email feature that could have exposed user email addresses, although it's unclear how often the flaw was exploited. The flaw was discovered by security researchers and disclosed to Apple in June 2025.

    osintsights.com/apple-rectifie

    #Icloud #HideMyEmail #EmailPrivacy #VulnerabilityDisclosure #Apple

  12. Apple Rectifies Hide My Email Flaw That Exposed User Addresses

    Apple has fixed a vulnerability in its Hide My Email feature that could have exposed user email addresses, although it's unclear how often the flaw was exploited. The flaw was discovered by security researchers and disclosed to Apple in June 2025.

    osintsights.com/apple-rectifie

    #Icloud #HideMyEmail #EmailPrivacy #VulnerabilityDisclosure #Apple

  13. Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.

    This week's Policy Pulse: blog.disclose.io/policy-pulse-

    #VulnerabilityDisclosure #CyberPolicy

  14. Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.

    This week's Policy Pulse: blog.disclose.io/policy-pulse-

    #VulnerabilityDisclosure #CyberPolicy

  15. Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.

    This week's Policy Pulse: blog.disclose.io/policy-pulse-

    #VulnerabilityDisclosure #CyberPolicy

  16. Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.

    This week's Policy Pulse: blog.disclose.io/policy-pulse-

    #VulnerabilityDisclosure #CyberPolicy

  17. Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.

    This week's Policy Pulse: blog.disclose.io/policy-pulse-

    #VulnerabilityDisclosure #CyberPolicy

  18. Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.

    The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.

    blog.disclose.io/dns-security-

    #infosec #DNS #VulnerabilityDisclosure

  19. Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.

    The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.

    blog.disclose.io/dns-security-

    #infosec #DNS #VulnerabilityDisclosure

  20. Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.

    The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.

    blog.disclose.io/dns-security-

    #infosec #DNS #VulnerabilityDisclosure

  21. Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.

    The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.

    blog.disclose.io/dns-security-

    #infosec #DNS #VulnerabilityDisclosure

  22. Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.

    The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.

    blog.disclose.io/dns-security-

    #infosec #DNS #VulnerabilityDisclosure

  23. Two new ways to find the right disclosure contact from your tooling:

    🔌 Disclosure Lookup is now in the official #Caido plugin store — right-click a request, get the verified security contact for that host.
    📦 dio-lookup is live on npm — pipe-friendly CLI: subfinder | httpx | dio-lookup

    Free + MIT-licensed, powered by lookup.disclose.io — Burp + Chrome extensions are in store review.

    Flag anything wrong — feedback feeds our accuracy audit.

    #InfoSec #BugBounty #VulnerabilityDisclosure

  24. Two new ways to find the right disclosure contact from your tooling:

    🔌 Disclosure Lookup is now in the official #Caido plugin store — right-click a request, get the verified security contact for that host.
    📦 dio-lookup is live on npm — pipe-friendly CLI: subfinder | httpx | dio-lookup

    Free + MIT-licensed, powered by lookup.disclose.io — Burp + Chrome extensions are in store review.

    Flag anything wrong — feedback feeds our accuracy audit.

    #InfoSec #BugBounty #VulnerabilityDisclosure

  25. Two new ways to find the right disclosure contact from your tooling:

    🔌 Disclosure Lookup is now in the official #Caido plugin store — right-click a request, get the verified security contact for that host.
    📦 dio-lookup is live on npm — pipe-friendly CLI: subfinder | httpx | dio-lookup

    Free + MIT-licensed, powered by lookup.disclose.io — Burp + Chrome extensions are in store review.

    Flag anything wrong — feedback feeds our accuracy audit.

    #InfoSec #BugBounty #VulnerabilityDisclosure

  26. Two new ways to find the right disclosure contact from your tooling:

    🔌 Disclosure Lookup is now in the official #Caido plugin store — right-click a request, get the verified security contact for that host.
    📦 dio-lookup is live on npm — pipe-friendly CLI: subfinder | httpx | dio-lookup

    Free + MIT-licensed, powered by lookup.disclose.io — Burp + Chrome extensions are in store review.

    Flag anything wrong — feedback feeds our accuracy audit.

    #InfoSec #BugBounty #VulnerabilityDisclosure

  27. Two new ways to find the right disclosure contact from your tooling:

    🔌 Disclosure Lookup is now in the official #Caido plugin store — right-click a request, get the verified security contact for that host.
    📦 dio-lookup is live on npm — pipe-friendly CLI: subfinder | httpx | dio-lookup

    Free + MIT-licensed, powered by lookup.disclose.io — Burp + Chrome extensions are in store review.

    Flag anything wrong — feedback feeds our accuracy audit.

    #InfoSec #BugBounty #VulnerabilityDisclosure

  28. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  29. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  30. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  31. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  32. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  33. Microsoft Revives Vulnerability Disclosure Debate with Researcher Crackdown

    Microsoft is stirring up controversy in the vulnerability disclosure debate, clashing with a security researcher over the responsible handling of zero-day vulnerabilities. The tech giant's strong response, including threats of legal action, has sparked heated discussion on coordinated disclosure.

    osintsights.com/microsoft-revi

    #VulnerabilityDisclosure #CoordinatedDisclosure #ZeroDay #Microsoft #ResponsibleDisclosure

  34. Microsoft Threatens Security Researcher Over Windows Exploits

    A mysterious security researcher known as "Nightmare Eclipse" has unleashed a string of powerful Windows exploits, including one that can bypass BitLocker, leaving Microsoft scrambling to respond. The bold move has sparked a tense standoff between the researcher and the tech giant.

    osintsights.com/microsoft-thre

    #WindowsExploits #Bitlocker #EmergingThreats #VulnerabilityDisclosure #Microsoft

  35. Microsoft Faces Backlash Over Zero-Day Disclosure Feud

    A researcher known as Nightmare Eclipse has unleashed a series of six Windows zero-day vulnerabilities, with working exploit code for at least three, and has threatened to release another on July 14, sparking a public feud with Microsoft. The ominous warning, which has left Microsoft speaking out against uncoordinated disclosures, has…

    osintsights.com/microsoft-face

    #ZeroDay #Windows #Microsoft #NightmareEclipse #VulnerabilityDisclosure

  36. CISA Opens KEV Nominations to Bolster Vulnerability Intelligence

    CISA is now accepting nominations for its Known Exploited Vulnerabilities catalog, empowering public reporting to strengthen the nation's cybersecurity posture by quickly identifying and mitigating exploited vulnerabilities. By submitting through the new KEV nomination form, you're helping to keep federal,…

    osintsights.com/cisa-opens-kev

    #VulnerabilityDisclosure #KnownExploitedVulnerabilities #Kev #Cisa #VulnerabilityIntelligence

  37. AI is fundamentally disrupting two core vulnerability cultures: the quiet fix and the long embargo. Advanced models like Gemini 3.1 Pro can now rapidly identify security patches, making discreet fixes and 90-day windows obsolete. This also challenges the 'stable version' paradigm, leaving older systems vulnerable to AI-driven exploits. A new era of continuous patching is here.

    tpp.blog/2nft9nn

    #AI #cybersecurity #vulnerabilitydisclosure

    🤖 This post was AI-generated.

  38. AI discovered 27-year-old OpenBSD bugs. 72% exploit rate. 99% unpatched.

    CSA + SANS + 100 CISOs published emergency guidance for vendors.

    Three assumptions just broke:
    - 90-day timelines don't work
    - You don't know if you're affected
    - Your process can't handle the volume

    Full analysis: bth.news/mythos-discovery

    #Cybersecurity #VulnerabilityDisclosure #InfoSec

  39. AI discovered 27-year-old OpenBSD bugs. 72% exploit rate. 99% unpatched.

    CSA + SANS + 100 CISOs published emergency guidance for vendors.

    Three assumptions just broke:
    - 90-day timelines don't work
    - You don't know if you're affected
    - Your process can't handle the volume

    Full analysis: bth.news/mythos-discovery

    #Cybersecurity #VulnerabilityDisclosure #InfoSec

  40. Lovable Disputes Data Leak, Shifts Blame to HackerOne

    Lovable, a coding platform, is facing scrutiny after a security researcher uncovered a major data leak, exposing users' sensitive information, including credentials, chat history, and source code, to anyone with a free account. The company's shifting explanations have only added fuel to the fire, sparking concerns about its data…

    osintsights.com/lovable-disput

    #DataLeak #CodingPlatform #VulnerabilityDisclosure #Hackerone #EmergingThreats

  41. CISA Pushes AI Firms to Join Vulnerability Disclosure Efforts

    The Cybersecurity and Infrastructure Security Agency (CISA) is calling on AI companies to take a more active role in disclosing vulnerabilities, sparking a crucial conversation about who's responsible for revealing flaws in AI systems. By joining forces, CISA and AI firms can work together to strengthen vulnerability…

    osintsights.com/cisa-pushes-ai

    #VulnerabilityDisclosure #ArtificialIntelligence #Cisa #EmergingThreats #AiSecurity

  42. We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

    Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

    For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

    srlabs.de/blog/hacking-ai-agent

    #AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

  43. We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

    Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

    For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

    srlabs.de/blog/hacking-ai-agent

    #AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

  44. We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

    Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

    For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

    srlabs.de/blog/hacking-ai-agent

    #AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

  45. We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

    Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

    For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

    srlabs.de/blog/hacking-ai-agent

    #AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

  46. We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

    Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

    For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

    srlabs.de/blog/hacking-ai-agent

    #AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

  47. The Ivanti EPMM zero-days underline a recurring issue: edge-facing management platforms remain prime targets.

    Confirmed incidents across EU institutions and government bodies show how quickly critical vulnerabilities can be weaponized. Even without confirmed device compromise, exposure of management infrastructure carries systemic risk.

    Source: technadu.com/ivanti-zero-day-v

    💬 Are edge device vulnerabilities becoming the dominant zero-day threat class?

    🔔 Follow @technadu for ongoing vulnerability and incident analysis

    #InfoSec #ZeroDay #Ivanti #MDM #EdgeSecurity #VulnerabilityDisclosure #CyberDefense #TechNadu

  48. The Ivanti EPMM zero-days underline a recurring issue: edge-facing management platforms remain prime targets.

    Confirmed incidents across EU institutions and government bodies show how quickly critical vulnerabilities can be weaponized. Even without confirmed device compromise, exposure of management infrastructure carries systemic risk.

    Source: technadu.com/ivanti-zero-day-v

    💬 Are edge device vulnerabilities becoming the dominant zero-day threat class?

    🔔 Follow @technadu for ongoing vulnerability and incident analysis

    #InfoSec #ZeroDay #Ivanti #MDM #EdgeSecurity #VulnerabilityDisclosure #CyberDefense #TechNadu

  49. The Ivanti EPMM zero-days underline a recurring issue: edge-facing management platforms remain prime targets.

    Confirmed incidents across EU institutions and government bodies show how quickly critical vulnerabilities can be weaponized. Even without confirmed device compromise, exposure of management infrastructure carries systemic risk.

    Source: technadu.com/ivanti-zero-day-v

    💬 Are edge device vulnerabilities becoming the dominant zero-day threat class?

    🔔 Follow @technadu for ongoing vulnerability and incident analysis

    #InfoSec #ZeroDay #Ivanti #MDM #EdgeSecurity #VulnerabilityDisclosure #CyberDefense #TechNadu

  50. The Ivanti EPMM zero-days underline a recurring issue: edge-facing management platforms remain prime targets.

    Confirmed incidents across EU institutions and government bodies show how quickly critical vulnerabilities can be weaponized. Even without confirmed device compromise, exposure of management infrastructure carries systemic risk.

    Source: technadu.com/ivanti-zero-day-v

    💬 Are edge device vulnerabilities becoming the dominant zero-day threat class?

    🔔 Follow @technadu for ongoing vulnerability and incident analysis

    #InfoSec #ZeroDay #Ivanti #MDM #EdgeSecurity #VulnerabilityDisclosure #CyberDefense #TechNadu

  51. Acknowledging Reality in Vulnerability Disclosure.

    Every few years, vulnerability disclosure is declared settled. We are told that the ecosystem has matured, that coordinated disclosure is the answer, and that whatever remains outside this model is either irresponsible, obsolete, or simply irrelevant.

    🔗 foo.be/2026/02/Acknowledging-R

    #vulnerabilitymanagement #gcve #cve #cybersecurity #cvd #vulnerabilitydisclosure #open

    This is my bloody personal blog, not an official statement. .

  52. Acknowledging Reality in Vulnerability Disclosure.

    Every few years, vulnerability disclosure is declared settled. We are told that the ecosystem has matured, that coordinated disclosure is the answer, and that whatever remains outside this model is either irresponsible, obsolete, or simply irrelevant.

    🔗 foo.be/2026/02/Acknowledging-R

    #vulnerabilitymanagement #gcve #cve #cybersecurity #cvd #vulnerabilitydisclosure #open

    This is my bloody personal blog, not an official statement. .

  53. Acknowledging Reality in Vulnerability Disclosure.

    Every few years, vulnerability disclosure is declared settled. We are told that the ecosystem has matured, that coordinated disclosure is the answer, and that whatever remains outside this model is either irresponsible, obsolete, or simply irrelevant.

    🔗 foo.be/2026/02/Acknowledging-R

    #vulnerabilitymanagement #gcve #cve #cybersecurity #cvd #vulnerabilitydisclosure #open

    This is my bloody personal blog, not an official statement. .

  54. Acknowledging Reality in Vulnerability Disclosure.

    Every few years, vulnerability disclosure is declared settled. We are told that the ecosystem has matured, that coordinated disclosure is the answer, and that whatever remains outside this model is either irresponsible, obsolete, or simply irrelevant.

    🔗 foo.be/2026/02/Acknowledging-R

    #vulnerabilitymanagement #gcve #cve #cybersecurity #cvd #vulnerabilitydisclosure #open

    This is my bloody personal blog, not an official statement. .

  55. Acknowledging Reality in Vulnerability Disclosure.

    Every few years, vulnerability disclosure is declared settled. We are told that the ecosystem has matured, that coordinated disclosure is the answer, and that whatever remains outside this model is either irresponsible, obsolete, or simply irrelevant.

    🔗 foo.be/2026/02/Acknowledging-R

    #vulnerabilitymanagement #gcve #cve #cybersecurity #cvd #vulnerabilitydisclosure #open

    This is my bloody personal blog, not an official statement. .