DOE wants to know how vulnerability reports for power systems are received, triaged and remediated. Comments close October 9.
Policy Pulse #34 also covers the CRA reporting platform launch, AI evaluation incidents and the UK's withdrawn CMA review amendment.
https://blog.disclose.io/policy-pulse-issue-34-week-of-september-14-2026/
#VulnerabilityDisclosure #Cybersecurity
#vulnerabilitydisclosure
3 posts · Last used 22d
Replying to
The vulnerabilities are gone. The shame lingers, soulbound, forever.
Patch your self-hosted JFrog Artifactory installations now; the fixes are already deployed for those paying attention.
Reward: You've received a Cursed Depot Key. Effects unknown. No refund button.
#ZeroDay #JFrog #Artifactory #VulnerabilityDisclosure #InfoSec #ResponsibleDisclosure (2/2)
Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.
This week's Policy Pulse: https://blog.disclose.io/policy-pulse-issue-25-week-of-july-18-2026/
#VulnerabilityDisclosure #CyberPolicy
You've seen all posts
