disclose.io

1.1K posts

disclose.io banner
disclose.io

disclose.io

@disclose_io

Free open-source tools to standardize, normalize, promote, and protect good-faith security research.

The Internet Katılım Nisan 2018
891 Takip Edilen2.9K Takipçiler
disclose.io
disclose.io@disclose_io·
Hackers on the Hill — June 16, US Capitol. Researchers and Hill staff, same room. Real 1:1 office briefings. No vendors. No shilling. If you build or break things for a living, the policy folks should hear it from you. Register: hackersonthehill.org/us-2026
English
0
0
0
31
disclose.io retweetledi
cje
cje@caseyjohnellis·
i'm seeing way, way more of these popping up over the past weeks/months, so i wanted to remind folks of some resources out there: - lookup.disclose.io (full reverse lookup w/ chaining and fallback contacts... MCP-enabled) - directory.disclose.io (~30,000 program directory w/ grading against @disclose_io maturity/safety model) - community.disclose.io (forum with folks willing to help make connections)
GIF
Tanner@wbmmfq

okay infosec twitter, I need some help. I came across an S3 bucket that has at least a million files of the insides of houses - some being lived in. i can't find a VDP for the company anywhere. what the fuck do i do?

English
0
15
33
5.6K
disclose.io
disclose.io@disclose_io·
Policy Pulse #14: UK AISI and Ireland's NCSC line up behind Project Glasswing. CyberUp ranks UK behind US, France, AU on researcher protection. CISA adds CVE-2026-31431 to KEV. blog.disclose.io/policy-pulse-i…
disclose.io tweet media
English
0
0
0
74
disclose.io
disclose.io@disclose_io·
Policy Pulse #13. AISI's GPT-5.5 eval confirms frontier-model offensive cyber is a trend, not a Mythos one-off. NIST drops enrichment for ~29,000 CVEs. UK is the only major western economy with no statutory defence for cyber pros. blog.disclose.io/policy-pulse-i…
disclose.io tweet media
English
0
0
1
84
disclose.io retweetledi
Tarjei Mandt
Tarjei Mandt@kernelpool·
Remember the time when everyone reported this stuff for free?
Looben Yang@loobeny

@GoogleVRP AI totally changed vulnerability research/ bug hunting. The Chrome VRP is officially dead. The reward amount is 10x less.

English
4
3
46
8.9K
disclose.io
disclose.io@disclose_io·
If you've received a cease-and-desist for security research, you're not alone. Cases that become public are the evidence base for CFAA reform and safe-harbor adoption. Lawyer first. Public record later, if you choose: blog.disclose.io/disclose-io-th…
English
0
0
2
59
disclose.io
disclose.io@disclose_io·
Policy Pulse #12: 13 new CVEs hit CISA's KEV catalog in 5 days. UK AISI publishes the first government evaluation of a frontier model's offensive cyber capabilities. CISA doesn't have access. blog.disclose.io/policy-pulse-i…
disclose.io tweet media
English
0
0
0
58
disclose.io retweetledi
Daniel Cuthbert
Daniel Cuthbert@dcuthbert·
A brilliant read by @ZephrFish on bullying LLMs at scale to find bugs. He delves into hallucinations and validation and also kindly did a hat tip to RAPTOR blog.zsec.uk/bullyingllms/ Well worth a hot drink and your time
English
2
18
62
4.1K
disclose.io retweetledi
Daniel Cuthbert
Daniel Cuthbert@dcuthbert·
Well that’s a story in itself
Daniel Cuthbert tweet media
English
0
3
12
1.6K
disclose.io retweetledi
disclose.io retweetledi
Dan Guido
Dan Guido@dguido·
Big skill drop from @trailofbits today! Here are 10 new skills we publicly released from our internal repository: 🧵
English
8
61
450
72.5K
disclose.io
disclose.io@disclose_io·
Policy Pulse #3: CISA orders unsupported edge devices eliminated, MITRE CVE contract 30 days from expiring, UK advancing statutory defence for researchers, and 3/4 of researchers report facing threats. blog.disclose.io/policy-pulse-i…
English
0
0
1
124
disclose.io
disclose.io@disclose_io·
Federal contractor VDP mandate advancing to Senate. 29% of exploited vulns attacked on or before CVE publication day. Policy Pulse covers the biggest shift in disclosure policy this year: blog.disclose.io/policy-pulse-i…
English
0
2
2
495
disclose.io retweetledi
bugcrowd
bugcrowd@Bugcrowd·
3️⃣ Silence is one of the biggest risks. A shocking 65% of hacker findings never reach defenders. Many hackers choose not to report bugs due to unclear or unsafe disclosure paths. ✅Why it matters: If reporting feels risky or pointless, critical issues stay hidden from those who can fix them.
English
1
1
1
107