Five governments (CISA, NSA, UK, NL, Japan) just published joint guidance on how to run a vulnerability disclosure program: safe harbor, security.txt, a CVE for every finding, no gag NDAs. Soft law, not statute, but now a citable five-government benchmark.
This week's Policy Pulse: https://blog.disclose.io/policy-pulse-issue-25-week-of-july-18-2026/
#VulnerabilityDisclosure #CyberPolicy
Remote
disclose.io 
@disclose@infosec.exchange
Free open-source tools to standardize, normalize, and promote the adoption of vulnerability reporting and disclosure. #internetimmunesystem #hacktheplanet
381 Followers
648 Following
5 Posts
Joined November 19, 2022
Github:
Get started…:
VDP Policy Generator:
Disclosure Assistance:
Researcher Threats DB:
Open post
Ahead of Hacker Summer Camp we've collected everything disclose.io makes on one page: the program directory, the security-contact lookup engine, safe-harbor terms, and the policy generators. All open source and free. We'll feature them one at a time from now to DEF CON. https://go.disclose.io/
0
0
0
0
Open post
Thanks everyone for your lookup.disclose.io feedback at #hackersummercamp this year, we got a TONNE of it and have made some pretty tasty updates over the weekend... 👀
• Owner-first routing: results lead with the owner's own reporting route
• New evidence panel: see why we attributed an asset
• Provenance + confidence on every contact
• One clear recommended next step
• Live progress instead of a spinner
Free, no login: https://lookup.disclose.io
0
0
0
0
Open post
DOE wants to know how vulnerability reports for power systems are received, triaged and remediated. Comments close October 9.
Policy Pulse #34 also covers the CRA reporting platform launch, AI evaluation incidents and the UK's withdrawn CMA review amendment.
https://blog.disclose.io/policy-pulse-issue-34-week-of-september-14-2026/
#VulnerabilityDisclosure #Cybersecurity
0
0
0
0
Open post
lookup.disclose.io passed 45,000 lookups.
Our dashboard says 143,690 requests. Most of it is MCP registry crawlers saying hello, so we are not calling that lookups. After basic bot filtering (user-agent based, and yes, bypassable) the number is 45,494.
Across 2,393 real assets people looked up, we found a disclosure route 41% of the time. The rest fell back to abuse@ or a national CERT: most of the internet still has nowhere to send a vuln report.
Go argue with the 59%.
lookup.disclose.io
0
0
0
0


