home.social

#vulnerabilitydisclosure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulnerabilitydisclosure, aggregated by home.social.

  1. Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.

    lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.

    Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.

    lookup.disclose.io

    #VulnerabilityDisclosure

  2. Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.

    lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.

    Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.

    lookup.disclose.io

    #VulnerabilityDisclosure

  3. Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.

    lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.

    Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.

    lookup.disclose.io

    #VulnerabilityDisclosure

  4. Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.

    lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.

    Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.

    lookup.disclose.io

    #VulnerabilityDisclosure

  5. Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.

    lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.

    Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.

    lookup.disclose.io

    #VulnerabilityDisclosure

  6. Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.

    This week's Policy Pulse: blog.disclose.io/policy-pulse-

    #VulnerabilityDisclosure #CyberPolicy

  7. We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

    Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

    For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

    srlabs.de/blog/hacking-ai-agent

    #AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure