Security News

Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy
2020-01-08 20:10

The more notable part of the announcement is Project Zero's decision to wait to disclose bug details until 90 days elapses, even if a patch becomes available before then. "For the last five years, the team has used its vulnerability disclosure policy to focus on one primary goal: Faster patch development," explained Willis, in a posting on Tuesday on the policy changes.

Google Project Zero Updates Vulnerability Disclosure Policy
2020-01-08 18:27

Google's Project Zero has updated its vulnerability disclosure policy to keep bug reports closed for 90 days, regardless of whether a patch is out before the deadline or not. The goal of this new policy, Google Project Zero's Tim Willis notes, goes beyond just attempting to speed up patching: thorough patch development and improved patch adoption are also a focus.

Blunt the Effect of the Two-Edged Sword of Vulnerability Disclosures
2019-12-10 20:29

When Hackers and Vendors Both Benefit, Your System May be the Biggest Loser read more

Moxa Addresses Industrial AP Vulnerabilities Several Months After Disclosure
2019-12-05 13:57

Moxa Urges Users to Replace Discontinued Industrial AP Filled With Security Holes read more

CISA Pushing U.S. Agencies to Adopt Vulnerability Disclosure Policies
2019-12-02 16:46

A newly proposed CISA directive would require all U.S. agencies to develop and implement vulnerability disclosure processes for their internet connected systems.

DHS Mandates Federal Agencies to Run Vulnerability Disclosure Policy
2019-11-27 21:34

The DHS is requiring all federal agencies to develop a vulnerability disclosure policy. The goal is that people who discover vulnerabilities in government systems have a mechanism for reporting...

How the Linux kernel balances the risks of public bug disclosure
2019-11-15 13:27

A serious Wi-Fi flaw shows how Linux handles security in plain sight.

Intel Warns of Critical Info-Disclosure Bug in Security Engine
2019-11-12 19:07

The issue is in an Intel chip used for remote management.

Former BAE Systems contractor charged with 'damaging disclosure' of UK defence secrets
2019-10-10 09:01

49-year-old to appear at the Old Bailey next month A former BAE Systems defence contractor has appeared in court accused of leaking "highly sensitive" secrets to foreign governments.…

How to handle the public disclosure of bugs and security vulnerabilities
2019-09-19 13:46

A full 90% of security professionals say yes, according to a poll conducted by 451 Research and commissioned by security testing company Veracode.