Sign in

disclose.io

@disclose.io
21 followers 2 following 78 posts
PostsRepliesMedia
disclose.io @disclose.io · 18/09/2026
When a site publishes no security contact, lookup.disclose.io says so plainly: "No first-party reporting route found." Constructed security@ ranks before abuse@, both labeled unverified, and a CERT route stays a real coordination path. And fewer results end there now. #VulnerabilityDisclosure
011
disclose.io @disclose.io · 17/09/2026
Look up an IP address in lookup.disclose.io and the answer is whoever is actually using it. Verified certificate subject, live redirects, and IP-hosted security.txt come first; the registered network holder and BGP origin are fallbacks; RPKI is routing context, never ownership.
000
disclose.io @disclose.io · 15/09/2026
The reporting contact is the first thing you see in a lookup.disclose.io result. Attribution and the evidence chain sit one section down. New below that: Historical Breadcrumbs, what the public web archive recorded for the domain, re-checked live and labeled as a lead, not ownership.
000
disclose.io @disclose.io · 14/09/2026
When a site's current security.txt names its disclosure platform, that wins. lookup.disclose.io drops conflicting program links from older third-party catalogs and keeps every platform the site itself publishes. No security.txt, or an expired one? Nothing gets suppressed.
000
disclose.io @disclose.io · 11/09/2026
security.txt results in lookup.disclose.io reflect what a site actually publishes. A TLS hostname edge case made valid files look missing on some very large sites. Fixed: /.well-known/ is checked first, an unreachable probe is not "absent," and expired files stay visible, labeled.
000
disclose.io @disclose.io · 10/09/2026
lookup.disclose.io has a proper usage guide. Domains, URLs, IPs, CIDRs, emails, and ASNs are detected automatically; when a bare name could mean several things, a prefix removes the ambiguity: npm:, pypi:, crates:, gh:, app:, hw:, ext:, desktop:. lookup.disclose.io/guide
000
disclose.io @disclose.io · 09/09/2026
lookup.disclose.io runs inside Nmap. lookup-disclose.nse enriches each public target with its owner and disclosure routes, refuses private targets, caps requests per scan, and never prints an API key. nmap -Pn -sn --script lookup-disclose example.com github.com/disclose/nmap-lookup
000
disclose.io @disclose.io · 08/09/2026
"Complete" in lookup.disclose.io means one thing: a reporting route qualified to the actual owner of the asset. A publisher, a repo host, a parent company, or a disclosure platform is useful context. As of September, a parent brand is context too, not disclosure scope. #AppSec
000
disclose.io @disclose.io · 04/09/2026
Plenty of organizations publish a solid disclosure policy that automated tools never find: behind bot protection, or deep in a help-center sitemap. lookup.disclose.io reaches those. Bunnings, TCL, and Motorola Solutions all publish one, and lookup finds it.
000
disclose.io @disclose.io · 03/09/2026
lookup.disclose.io runs inside the tools you already use: dio-lookup CLI (npm), Caido plugin, Burp and OWASP ZAP extensions, Chrome extension, Nmap NSE, Nuclei templates, a hosted MCP server, and a plain JSON API. Every one is a thin client over the same production API. github.com/disclose
000
disclose.io @disclose.io · 07/07/2026
two new ways to find where to report a vuln: the Disclosure Lookup plugin is now in the official Caido plugin store, and the dio-lookup CLI is on npm (subfinder | httpx | dio-lookup 🤌) free + open source, powered by m.disclose.io/4vhETLd — kick the tires and tell us what's wrong 🙏
000
disclose.io @disclose.io · 09/05/2026
Policy Pulse Issue #14: UK and Ireland line up behind Project Glasswing as Mythos forces a new disclosure reality. CyberUp ranks the UK behind US, France, and Australia on researcher protections. blog.disclose.io/policy-pulse-issue…
000
disclose.io @disclose.io · 06/04/2026
Policy Pulse #9: OWASP's Agentic AI Top 10 redefines what VDP programs need to handle. Plus: OpenAI safety bounty, Langflow exploited in 20hrs, GSA's first AI acquisition clause. blog.disclose.io/policy-pulse-issue…
000
disclose.io @disclose.io · 29/03/2026
The CVE program is "saved" by a mystery contract with a mystery number. Transparency? Not so much. Plus: lookup.disclose.io beta is live, EU CRA hits 6 months, exploited vulns up 105%. Policy Pulse #8: blog.disclose.io/policy-pulse-issue… #CVE #PolicyPulse
001