Sign in

disclose.io

@disclose.io
21 followers 2 following 77 posts
PostsRepliesMedia
disclose.io @disclose.io · 21/09/2026
lookup.disclose.io passed 45,000 lookups. Our dashboard says 143,690 requests. Most of that is MCP crawlers saying hello, so after basic bot filtering we call it 45,494. 41% of 2,393 real assets resolved to a disclosure route. The rest is most of the internet having nowhere to send a report.
000
disclose.io @disclose.io · 20/09/2026
OpenAI's bounty paid for the in-scope half of a forum-to-employee-account chain. Policy Pulse #35 covers the scope question, an unclear libheif CVE mapping and Anthropic's outside-evaluator commitment. blog.disclose.io/policy-pulse...
blog.disclose.io
Policy Pulse - Issue #35 | Week of September 20, 2026
OpenAI's bounty paid for the in-scope half of a chain that began on a Discourse forum, and the libheif CVE mapping is unclear. Plus Anthropic's evaluator commitment, California's IVO laws and ENISA's…
000
disclose.io @disclose.io · 18/09/2026
When a site publishes no security contact, lookup.disclose.io says so plainly: "No first-party reporting route found." Constructed security@ ranks before abuse@, both labeled unverified, and a CERT route stays a real coordination path. And fewer results end there now. #VulnerabilityDisclosure
011
disclose.io @disclose.io · 17/09/2026
Look up an IP address in lookup.disclose.io and the answer is whoever is actually using it. Verified certificate subject, live redirects, and IP-hosted security.txt come first; the registered network holder and BGP origin are fallbacks; RPKI is routing context, never ownership.
000
disclose.io @disclose.io · 16/09/2026
Who is lookup.disclose.io for? Anyone who found something on an asset they don't own and needs to reach whoever does. Researchers first, but also IR and threat intel, SOC and abuse desks, CERTs, product security, CNAs, and anyone building agentic tooling. lookup.disclose.io/how-it-works
000
disclose.io @disclose.io · 15/09/2026
The reporting contact is the first thing you see in a lookup.disclose.io result. Attribution and the evidence chain sit one section down. New below that: Historical Breadcrumbs, what the public web archive recorded for the domain, re-checked live and labeled as a lead, not ownership.
000
disclose.io @disclose.io · 14/09/2026
DOE wants to know how power-system vulnerability reports reach a fix. Comments close October 9. Policy Pulse #34 covers the consultation, CRA reporting and AI evaluation incidents. blog.disclose.io/policy-pulse...
blog.disclose.io
Policy Pulse - Issue #34 | Week of September 14, 2026
DOE asks how power-system vulnerability reports reach a fix. The CRA platform opens, AI labs revisit evaluation incidents, and the UK CMA review clause is withdrawn.
000
disclose.io @disclose.io · 14/09/2026
When a site's current security.txt names its disclosure platform, that wins. lookup.disclose.io drops conflicting program links from older third-party catalogs and keeps every platform the site itself publishes. No security.txt, or an expired one? Nothing gets suppressed.
000
disclose.io @disclose.io · 12/09/2026
dnssecuritytxt census, Sep 7: 216 domains publish a security contact in DNS, net +20. New: one.com + 19 more group.one brands (incl. WP Rocket, Imagify), @defcon.bsky.social's defcon.social, Concordia Univ. of Edmonton, Skatteverket, Steno (legal tech). One TXT record: dnssecuritytxt.org
034
disclose.io @disclose.io · 11/09/2026
security.txt results in lookup.disclose.io reflect what a site actually publishes. A TLS hostname edge case made valid files look missing on some very large sites. Fixed: /.well-known/ is checked first, an unreachable probe is not "absent," and expired files stay visible, labeled.
000
disclose.io @disclose.io · 10/09/2026
lookup.disclose.io has a proper usage guide. Domains, URLs, IPs, CIDRs, emails, and ASNs are detected automatically; when a bare name could mean several things, a prefix removes the ambiguity: npm:, pypi:, crates:, gh:, app:, hw:, ext:, desktop:. lookup.disclose.io/guide
000
disclose.io @disclose.io · 09/09/2026
lookup.disclose.io runs inside Nmap. lookup-disclose.nse enriches each public target with its owner and disclosure routes, refuses private targets, caps requests per scan, and never prints an API key. nmap -Pn -sn --script lookup-disclose example.com github.com/disclose/nmap-lookup
000
disclose.io @disclose.io · 08/09/2026
"Complete" in lookup.disclose.io means one thing: a reporting route qualified to the actual owner of the asset. A publisher, a repo host, a parent company, or a disclosure platform is useful context. As of September, a parent brand is context too, not disclosure scope. #AppSec
000
disclose.io @disclose.io · 06/09/2026
Three frontier AI labs made cyber-capability calls within 72 hours: OpenAI's first Critical-rated model, a vetted-only Gemini Cyber, and Anthropic's own eval pause after sandbox escapes. Policy Pulse #33: blog.disclose.io/policy-pulse...
blog.disclose.io
Policy Pulse - Issue #33 | Week of September 6, 2026
OpenAI's Astra hits Critical on cyber capability, Google gates Gemini Cyber to vetted defenders, and Anthropic paused external safety testing right as both happened. Plus a live UK CMA reform clause…
000
disclose.io @disclose.io · 04/09/2026
Plenty of organizations publish a solid disclosure policy that automated tools never find: behind bot protection, or deep in a help-center sitemap. lookup.disclose.io reaches those. Bunnings, TCL, and Motorola Solutions all publish one, and lookup finds it.
000
disclose.io @disclose.io · 03/09/2026
lookup.disclose.io runs inside the tools you already use: dio-lookup CLI (npm), Caido plugin, Burp and OWASP ZAP extensions, Chrome extension, Nmap NSE, Nuclei templates, a hosted MCP server, and a plain JSON API. Every one is a thin client over the same production API. github.com/disclose
000
disclose.io @disclose.io · 01/09/2026
Policy Pulse #32: Trail of Bits gave GPT-5.6-Cyber one task: escape the VM. It did, three times, twice on bugs nobody had labelled as security issues. Disclosure record so far: "bug has been reported." blog.disclose.io/policy-pulse...
blog.disclose.io
Policy Pulse - Issue #32 | Week of September 1, 2026
A preview cyber model escaped a stock VM three times on bugs nobody had labelled as security issues, and its disclosure trail is one line. Plus IST's Fragile Foundations sprint and PaperCut on KEV.
000
disclose.io @disclose.io · 23/08/2026
Policy Pulse #30: Mandiant's agentic review harness found more than 100 true-positive critical vulns in two days. The volume is not the story. The human validation gate is. blog.disclose.io/policy-pulse...
blog.disclose.io
Policy Pulse - Issue #30 | Week of August 23, 2026
Mandiant found more than 100 critical flaws in two days with an agentic review harness. NIST opened two new comment windows, and CISA added nine actively exploited vulnerabilities.
000
disclose.io @disclose.io · 16/08/2026
Policy Pulse #29: the White House licensed private firms to hack back, and never touched the CFAA. No civil safe harbor, Crowell & Moring warns. blog.disclose.io/policy-pulse...
blog.disclose.io
Policy Pulse - Issue #29 | Week of August 16, 2026
The White House authorizes vetted private firms to run offensive cyber operations, with no CFAA safe harbor in sight. NIST opens a 60-day RFI on rebuilding the NVD, and OpenAI ships a purpose-built…
001
disclose.io @disclose.io · 15/08/2026
Months after NIST said most new CVEs are lowest priority for enrichment, it's asking what the NVD should become in the AI era. Disclosure programs are named in the architecture. Comments close Oct 13. Our analysis: blog.disclose.io/nvd-moderniz... #NVD #infosec
blog.disclose.io
NIST Wants to Modernize the NVD. Disclosure Should Be Part of the Answer.
NIST is asking how to rebuild the NVD for the AI era, and vulnerability disclosure programs are named in the architecture. Comments close October 13. Here's what a useful response looks like.
000
disclose.io @disclose.io · 13/08/2026
A new White House memo directs a federal program authorizing vetted private companies to hack foreign cybercrime orgs, under DOJ and DHS oversight. Our factual read of what it says and what it doesn't: blog.disclose.io/white-house-...
blog.disclose.io
What the White House's New Private-Sector Cyber Operations Memo Actually Says (and What It Doesn't)
The August 12 memorandum authorizes vetted private companies to conduct cyber operations under federal control. What it says, what it doesn't, and why authorization is the hinge.
000
disclose.io @disclose.io · 11/08/2026
Leonard Bailey's BSidesLV 2026 keynote: the inside story of how hackers and the DOJ built the 2022 good-faith security research charging policy. Write-up and video cued to the talk: blog.disclose.io/watch-how-ha...
blog.disclose.io
https://blog.disclose.io/watch-how-hackers-helped-the-doj-protect-security-researchers/
000
disclose.io @disclose.io · 11/08/2026
Monthly dnssecuritytxt census: 195 domains now publish security contact info in DNS, up 6 this month. New adopters include FIRST, SANS ISC, and SIDN Labs. One TXT record tells researchers where to report vulnerabilities in anything on your domain. Takes five minutes: dnssecuritytxt.org
dnssecuritytxt.org
DNS Security TXT
A standard for nominating security contact points and policies via DNS TXT records, discoverable before a researcher even loads your site.
000
disclose.io @disclose.io · 10/08/2026
Policy Pulse #28: Latvia drafts a researcher safe harbor that protects outcomes, not intent. Germany would pipe BSI zero-days to the BND. Plus the Ninth Circuit on AI agents and the CFAA. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-28-week-of-august-10-2026/
000
disclose.io @disclose.io · 10/08/2026
That wraps the series. PolicyPulse is our policy newsletter, and everything we featured this week is collected at go.disclose.io.
000
disclose.io @disclose.io · 07/08/2026
disclose.io/threats is our ongoing archive of legal threats against good-faith security research. We publish our own vulnerability disclosure policy too, at disclose.io/security.
000
disclose.io @disclose.io · 06/08/2026
If you're arriving for DEF CON, everything we make is collected at go.disclose.io: the program directory, the security-contact lookup, safe-harbor terms, and the policy generators. It's all open source, vendor-neutral, and free.
010
disclose.io @disclose.io · 05/08/2026
The disclose.io framework is standardized disclosure and safe-harbor language, released under CC0. policymaker.disclose.io turns it into a policy, a safe-harbor clause, and a security.txt in one pass.
000
disclose.io @disclose.io · 04/08/2026
state.disclose.io summarizes disclosure adoption. The Top 100 scoreboards score the Fortune 100, ASX 100, and FTSE 100 against the maturity model, based on their published policies: state.disclose.io/top-100
000
disclose.io @disclose.io · 03/08/2026
The disclose.io program directory tracks more than 27,500 organizations with a VDP or bug bounty program, graded against the maturity model. It's free to search and open to contributions: directory.disclose.io
000
disclose.io @disclose.io · 01/08/2026
dnssecuritytxt is an open specification for publishing your security contact at the DNS layer. It sits alongside security.txt. 180+ domains publish the record, and the generator at dnssecuritytxt.org will write yours for you.
000
disclose.io @disclose.io · 31/07/2026
Some tooling for the week ahead. dio-lookup on npm returns security contacts for piped assets as JSONL. Our nuclei templates annotate scanned hosts with their disclosure contact. The Disclosure Lookup plugin is in the Caido store. More at go.disclose.io
000
disclose.io @disclose.io · 30/07/2026
lookup.disclose.io resolves a domain, IP, repo, package, or app to the organization responsible and its published security contact. Web UI, JSON API, and a hosted MCP server for agents.
010
disclose.io @disclose.io · 29/07/2026
Ahead of Hacker Summer Camp: everything disclose.io makes, collected on one page. Program directory, security-contact lookup, safe-harbor terms, policy generators. Open source, vendor-neutral, free. go.disclose.io
go.disclose.io
https://go.disclose.io/
000
disclose.io @disclose.io · 19/07/2026
Five governments (CISA, NSA, UK, NL, Japan) just told vendors exactly how to run a VDP: safe harbor, security.txt, a CVE for every finding, no gag NDAs. This week's Policy Pulse: blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-25-week-of-july-18-2026/
000
disclose.io @disclose.io · 14/07/2026
Publish your security contact in DNS. Five years on, DNS Security TXT has one canonical home (_security), a required expiry field, and 181 domains found publishing in the wild, from gov.uk to DEF CON. blog.disclose.io/dns-security... #infosec #dns
blog.disclose.io
https://blog.disclose.io/dns-security-txt-five-years-on/
000
disclose.io @disclose.io · 12/07/2026
Policy Pulse #24: GPT-5.6 Sol goes public as Washington lifts its access gate, and UK AISI finds universal cyber jailbreaks within hours, the same pattern that forced Fable 5 offline. Plus Illinois mandates frontier AI audits. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-24-week-of-july-11-2026/
010
disclose.io @disclose.io · 07/07/2026
Reaching the right security contact shouldn't take all afternoon. lookup.disclose.io now works where you do: a CLI, Caido and Burp plugins, and an MCP server for AI agents. Try it, and tell us what breaks: blog.disclose.io/bring-lookup...
blog.disclose.io
https://blog.disclose.io/bring-lookup-disclose-io-into-your-workflow/
020
disclose.io @disclose.io · 07/07/2026
two new ways to find where to report a vuln: the Disclosure Lookup plugin is now in the official Caido plugin store, and the dio-lookup CLI is on npm (subfinder | httpx | dio-lookup 🤌) free + open source, powered by m.disclose.io/4vhETLd — kick the tires and tell us what's wrong 🙏
000
disclose.io @disclose.io · 06/07/2026
lookup.disclose.io finds the security contact for any asset (domain, ip, package, repo, container, extension) and now plugs into recon: dio-lookup cli, caido + burp plugins, json api, and mcp server. plus directory.disclose.io grades programs against our maturity model.
lookup.disclose.io
https://lookup.disclose.io
000
disclose.io @disclose.io · 05/07/2026
Two new additions to our open bug bounty & VDP platform directory: 🇨🇳 360 SRC — crowdsourced vuln response 🤖 HackAPrompt — AI red-teaming contests It's fully open source & community-maintained. Spot a gap? Send a PR 👇 github.com/disclose/bug-bounty-platforms
000
disclose.io @disclose.io · 05/07/2026
Policy Pulse #23: The US lifts export controls on Anthropic's Mythos 5 and Fable 5, while OpenAI's GPT-5.6 Sol stays behind the government access wall. Plus the Linux Foundation launches Akrites for AI-scale disclosure. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-23-week-of-july-4-2026/
000
disclose.io @disclose.io · 30/06/2026
Safe harbor makes it safe to report a bug. The other half, talked about less: report well. Our cross-post of Daniel Stenberg's (curl) guide to vulnerability reports that actually get fixed: blog.disclose.io/what-makes-a...
blog.disclose.io
https://blog.disclose.io/what-makes-a-vulnerability-report-excellent/
000
disclose.io @disclose.io · 29/06/2026
Policy Pulse #22: GPT-5.6 Sol joins Mythos 5 behind the US government's frontier AI access wall. UK CMA reform's statutory defence covers only 300 of 69,600 researchers. DMCA Section 1201 petitions open through Aug 24. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-22-week-of-june-28-2026/
000
disclose.io @disclose.io · 28/06/2026
Policy Pulse #21: Commerce partially lifted the export-control block on Anthropic's offensive cyber models. Mythos 5 is cleared for 100-plus US critical-infra orgs, Fable 5 stays blocked, and it is rhyming with Wassenaar. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-21-week-of-june-27-2026/
000
disclose.io @disclose.io · 26/06/2026
Finding a bug is human work; getting it to the right inbox shouldn't be hard — but it still is. lookup.disclose.io resolves any asset to the right security contact, now with a hosted MCP server + API. What input types are we missing? blog.disclose.io/coordination...
blog.disclose.io
https://blog.disclose.io/coordination-is-going-api-first/
110
disclose.io @disclose.io · 21/06/2026
Policy Pulse #20: 3 days after Anthropic shipped an offensive cyber model to defenders, the US govt used export control to recall it worldwide. The first govt recall of a deployed frontier cyber model. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-20-week-of-june-20-2026/
000
disclose.io @disclose.io · 15/06/2026
Policy Pulse #19: EO 14409 tells the government how to benchmark AI-found vulnerabilities, and nothing about how they reach defenders. Plus: CISA opens KEV to researchers, and the NVD backlog. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-19-week-of-june-13-2026/
000
disclose.io @disclose.io · 13/06/2026
The first qualitative study of researchers' lived experiences of legal risk (Park & Thomas, USENIX Security '26): the CFAA and UK CMA chill good-faith research — and it names disclose.io as part of the fix. blog.disclose.io/above-the-pa...
blog.disclose.io
https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts/
000
disclose.io @disclose.io · 07/06/2026
Policy Pulse #18 is out. Hackers on the Hill returns to DC on June 16. The week around it: AI cybersecurity EO signed, EU CRA clock ticking, UK CMA defence narrowing. The policymaker meetings just got unusually consequential. blog.disclose.io/policy-pulse...
blog.disclose.io
https://blog.disclose.io/policy-pulse-issue-18-week-of-june-6-2026/
000