Skip to content

Topic

Coordinated Vulnerability Disclosure

A process where security researchers privately report vulnerabilities to vendors, allowing time to develop fixes before public disclosure.

Current stories

leadership3 publishers

Guardrails that blocked Hugging Face's responders put AI access on the incident plan

Commercial AI models refused every query from Hugging Face's breach responders, Veracode's Chris Wysopal wrote, forcing them onto a self-hosted Chinese model. Security leaders now have to settle which AI model their responders can use before an intrusion starts.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 45%
Investor
Investor 33%

Reality

Evidence45
Adoption
Insufficient
Hype gap+30
Incentives55
Confidence50
security6 publishers

Encrypted prompts walk past Grok and Gemini guardrails, and no one owns the bug

Adversa AI says its Cryptographic Context Injection recovers hostile prompts inside the code sandbox, where filters do not look. xAI has not replied; Google scopes jailbreaks out entirely.

Perspective Coverage

6 publishers
Builder
Builder 34%
Operator
Operator 55%
Investor
Investor 11%

Reality

Evidence50
Adoption
Insufficient
Hype gap+30
Incentives55
Confidence55
security4 publishers

Two chained flaws reach root on Unitree's G1 humanoid from Bluetooth range

Olivier Laflamme walked an unpaired Bluetooth write up to root on the G1 EDU's Locomotion PC by way of a Unitree cloud API that decrypted key material for any logged-in account. Unitree fixed that check in July, but no patched firmware has been named.

Publishers:boschko.cascworld.comsecurityaffairs.comthehackernews.com

Perspective Coverage

4 publishers
Builder
Builder 38%
Operator
Operator 50%
Investor
Investor 12%

Reality

Evidence72
Adoption38
Hype gap+8
Incentives45
Confidence62
security8 publishers

Exposed MikroTik SSH hands over full administrative control without authentication

CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.

Perspective Coverage

8 publishers
Builder
Builder 19%
Operator
Operator 73%
Investor
Investor 8%

Reality

Evidence78
Adoption45
Hype gap+18
Incentives30
Confidence72
security3 publishers

MikroTik's new RouterOS builds check whether the device was already compromised

MikroTik published RouterOS fixes in four branches with no CVE and no technical detail. The same upgrade runs a compromise check and writes a critical log entry marking the device Flagged.

Publishers:cert.plforum.mikrotik.comhelpnetsecurity.com

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 71%
Investor
Investor 7%

Reality

Evidence76
Adoption
Insufficient
Hype gap−40
Incentives45
Confidence72

Earlier coverage

  1. Opening a stranger's repo in OpenAI Codex handed its author commands on the host

    Security · September 20, 2026 · 1 publisher

  2. CISA moves vulnerability coordination off CERT/CC's VINCE onto its own platform

    Security · September 18, 2026 · 2 publishers

  3. A CNAME left pointing at a deleted S3 bucket hands the subdomain to whoever registers the name first

    Build · September 17, 2026 · 1 publisher

  4. Replaying camera traffic on the LAN gets admin on TP-Link's Tapo C200

    Security · September 16, 2026 · 1 publisher

  5. A crafted URL runs attacker script inside an authenticated Teamcenter session

    Security · September 16, 2026 · 1 publisher

  6. Researchers Show Encrypted Reasoning Blocks From OpenAI, Anthropic and Google Can Be Decrypted Using a Weaker Sibling Model

    Build · September 15, 2026 · 1 publisher

  7. Two of seven unpatched CareCam CM2507 camera flaws let anyone on the network view live video

    Security · September 15, 2026 · 1 publisher

  8. ENISA puts weaponisation of a disclosed vulnerability at 15 minutes

    Security · September 14, 2026 · 1 publisher

  9. Ten days of maintainer time bought Core Lightning a two-week embargo on AI-found bugs

    Invest · August 27, 2026 · 3 publishers

  10. Opening the cohttp fix PR drew traversal probes within ten minutes

    Build · September 11, 2026 · 1 publisher

  11. An encrypted payload turns Grok's own navigation tool into the exfiltration path

    Build · September 10, 2026 · 1 publisher

  12. Authenticated SQL in Mirth Connect hands over the credentials for the systems it connects to

    Security · September 10, 2026 · 1 publisher

  13. Anthropic hands an unreleased bug-finding model to more than 50 organisations

    Security · September 9, 2026 · 1 publisher

  14. Gamers Nexus teardown finds LG TVs inventorying the LAN they sit on

    Security · September 8, 2026 · 2 publishers

  15. Ledger's lab took about 125 days to walk a laser flaw in Trezor's chip into public view

    Invest · September 7, 2026 · 1 publisher

  16. Apple's report cap blocked a seven-person firm with a patched Mac bug to its name

    Product · September 5, 2026 · 1 publisher

  17. Community maps in MECCHA CHAMELEON could write files anywhere on a player's disk

    Security · September 5, 2026 · 1 publisher

  18. Rockwell's ControlFLASH installer gave the Everyone group write access to its own program folder

    Security · September 3, 2026 · 1 publisher

  19. Rockwell answers a 1756-ENBT crash bug with a hardware swap instead of firmware

    Security · September 3, 2026 · 1 publisher

  20. A dropped authorization check exposes GeoNetwork geoportal backends to unauthenticated RCE

    Security · September 2, 2026 · 1 publisher

  21. OpenAI holds two unpatched zero-days its own benchmark run produced

    Invest · September 2, 2026 · 1 publisher

  22. Rockwell's redundancy config tool loads a standard user's DLL as SYSTEM

    Security · September 1, 2026 · 1 publisher

  23. Cosmos Labs ran incident command for forty chains it does not operate

    Leadership · August 30, 2026 · 1 publisher

  24. Polygon fixed a validator-stalling bug in two hard forks before saying what it was

    Invest · August 29, 2026 · 2 publishers

  25. MIT's TONTOU attack reaches protected Linux memory through a two-instruction window

    Product · August 28, 2026 · 1 publisher

  26. Xiiaozet's LK100W lets an unauthenticated caller switch on its admin services

    Security · August 27, 2026 · 1 publisher

  27. N-able Passportal leaked whole vaults to any page: v3.49.6 stops the leak, not the tokens

    Security · August 26, 2026 · 1 publisher

  28. CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering

    Security · August 25, 2026 · 1 publisher

  29. Provenance's marker module let anyone with zero tokens claim admin over 82 live financial assets

    Security · August 25, 2026 · 1 publisher

  30. A machine found the bug and set the clock: Ledger disputes TestMachine's timeline

    Security · August 25, 2026 · 1 publisher

  31. Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache

    Security · August 23, 2026 · 1 publisher

  32. Your edge speaks HTTP/3, your origin speaks HTTP/1.1: that gap is now a DoS primitive

    Build · August 21, 2026 · 1 publisher

  33. MLflow's default server hands out cloud credentials to anyone who asks nicely

    Leadership · August 20, 2026 · 1 publisher

  34. Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions

    Security · August 20, 2026 · 1 publisher

  35. Akrites switches on in September with 20-odd members and a one-to-10 engineer donation band

    Security · August 19, 2026 · 1 publisher

  36. A config file that runs shell commands: "open this in Claude Code" needs a review gate

    Leadership · August 19, 2026 · 1 publisher

  37. A researcher is timing zero-days to Patch Tuesday, and the monthly cadence has no reply

    Build · August 19, 2026 · 1 publisher

  38. Kimi Desktop's second binary: mutable CDN path, no Windows checksum, no signer check

    Build · August 18, 2026 · 1 publisher

  39. Windows 11's secure kernel trusts a RAM chip that never checks who is writing to it

    Security · August 17, 2026 · 1 publisher

  40. White-on-white PDF makes Atlassian's Rovo leak Jira and Confluence data; the org switch does not help

    Build · August 15, 2026 · 1 publisher