# Running With Scissors - The Disclose.io Blog > Hacking, policy, advocacy, and the sharp edges of security research. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [About this site](https://blog.disclose.io/about.md) - The disclose.io Blog is an independent publication launched in February 2026 by Disclose.io. If you subscribe today, you'll get full access to the website as well as email newsletters about new content when it's available. Your subscription makes this site possible, and allows The disclose.io Blog… - [Upcoming Dates](https://blog.disclose.io/upcoming-dates.md) - Key dates for the vulnerability disclosure and security research community: policy comment deadlines, regulations, CFPs, and international developments. ## Posts - [Policy Pulse - Issue #29 | Week of August 16, 2026](https://blog.disclose.io/policy-pulse-issue-29-week-of-august-16-2026.md) - The White House authorizes vetted private firms to run offensive cyber operations, with no CFAA safe harbor in sight. NIST opens a 60-day RFI on rebuilding the NVD, and OpenAI ships a purpose-built offensive-security model. - [NIST Wants to Modernize the NVD. Disclosure Should Be Part of the Answer.](https://blog.disclose.io/nvd-modernization-rfi-2026.md) - NIST is asking how to rebuild the NVD for the AI era, and vulnerability disclosure programs are named in the architecture. Comments close October 13. Here's what a useful response looks like. - [What the White House's New Private-Sector Cyber Operations Memo Actually Says (and What It Doesn't)](https://blog.disclose.io/white-house-private-sector-cyber-operations-memo.md) - The August 12 memorandum authorizes vetted private companies to conduct cyber operations under federal control. What it says, what it doesn't, and why authorization is the hinge. - [Policy Pulse - Issue #28 | Week of August 10, 2026](https://blog.disclose.io/policy-pulse-issue-28-week-of-august-10-2026.md) - Latvia opens comments on a statutory safe harbor that protects outcomes, not intent. Germany's draft reform would order the BSI to hand zero-days to the BND. Plus the Ninth Circuit on AI agents and the CFAA. - [Watch: How Hackers Helped the DOJ Protect Security Researchers](https://blog.disclose.io/watch-how-hackers-helped-the-doj-protect-security-researchers.md) - Leonard Bailey's BSidesLV 2026 keynote tells the inside story of the DOJ's good-faith security research policy, and how the hacker community helped make it happen. Watch it here. - [Policy Pulse - Issue #27 | Week of August 1, 2026](https://blog.disclose.io/policy-pulse-issue-27-week-of-august-1-2026.md) - Anthropic discloses three Claude models breached three real organizations during cyber evals, days after OpenAI breached Hugging Face the same way. Congress pushes the FRONTIER Act as CISA's 2015 sharing law nears sunset. - [Policy Pulse - Issue #26 | Week of July 25, 2026](https://blog.disclose.io/policy-pulse-issue-26-week-of-july-25-2026.md) - OpenAI's own evaluation models breached Hugging Face, triggering a bipartisan AI Kill Switch bill within 48 hours. A federal judge separately orders published iPhone exploit research deleted on trade-secret grounds. - [Policy Pulse - Issue #25 | Week of July 18, 2026](https://blog.disclose.io/policy-pulse-issue-25-week-of-july-18-2026.md) - CISA, NSA, and allied agencies from the UK, Netherlands, and Japan jointly tell vendors how to run a VDP, safe-harbor language included. Plus: AI-scale disclosure overwhelms maintainers, and the White House launches Gold Eagle. - [DNS Security TXT, Five Years On](https://blog.disclose.io/dns-security-txt-five-years-on.md) - Five years after we proposed publishing your security contact in DNS, the standard has one canonical home, a required freshness field, an Internet-Draft, and 181 domains found in the wild. - [Policy Pulse - Issue #24 | Week of July 11, 2026](https://blog.disclose.io/policy-pulse-issue-24-week-of-july-11-2026.md) - GPT-5.6 Sol goes public as Washington lifts its access gate, and UK AISI finds universal cyber jailbreaks within hours, the same pattern that forced Anthropic's Fable 5 offline. Plus Illinois mandates frontier AI safety audits. - [Bring lookup.disclose.io Into Your Workflow](https://blog.disclose.io/bring-lookup-disclose-io-into-your-workflow.md) - lookup.disclose.io now plugs into the tools you already use: a CLI, Caido and Burp Suite plugins, an MCP server for AI agents, plus the web app and API. Try them, and tell us what to fix. - [Policy Pulse - Issue #23 | Week of July 4, 2026](https://blog.disclose.io/policy-pulse-issue-23-week-of-july-4-2026.md) - Washington lifts export controls on Anthropic's frontier cyber models two weeks after locking them down. Plus Akrites launches to absorb AI-scale disclosure and ENISA's CVE Root appoints a new CNA. - [What Makes a Vulnerability Report Excellent](https://blog.disclose.io/what-makes-a-vulnerability-report-excellent.md) - curl maintainer Daniel Stenberg has triaged 1,000+ vulnerability reports. His field guide on reporting well is the other half of safe harbor — and the antidote to AI-generated slop. - [Policy Pulse - Issue #22 | Week of June 28, 2026](https://blog.disclose.io/policy-pulse-issue-22-week-of-june-28-2026.md) - GPT-5.6 Sol joins Mythos 5 behind the federal access wall as the US government locks in its frontier AI gatekeeping regime. UK CMA reform's statutory defence covers only 300 of 69,600 researchers. DMCA Section 1201 petitions open through August 24. - [Feedback Requested: Coordination is going API-first. Contact Discovery and Attribution still aren't solved.](https://blog.disclose.io/coordination-is-going-api-first.md) - Vulnerability coordination is going API- and MCP-driven, but attribution and contact discovery are still the hard part. What's new in lookup.disclose.io — and where we want your feedback. - [Policy Pulse - Issue #20 | Week of June 20, 2026](https://blog.disclose.io/policy-pulse-issue-20-week-of-june-20-2026.md) - Three days after Anthropic shipped Mythos 5 to vetted defenders, the US government used export control to recall it worldwide. CISA's BOD 26-04 also retires the fixed-deadline KEV model for a risk score. - [Policy Pulse - Issue #19 | Week of June 13, 2026](https://blog.disclose.io/policy-pulse-issue-19-week-of-june-13-2026.md) - Trump's Executive Order 14409 stands up a federal AI cybersecurity clearinghouse, but benchmarks machine-found vulnerabilities while saying nothing about how they reach defenders. Plus: CISA opens KEV nominations to researchers. - [Above the Parapets: The Chilling Effect Finally Has Receipts](https://blog.disclose.io/above-the-parapets-the-chilling-effect-finally-has-receipts.md) - The first qualitative study of researchers' lived experiences of legal risk: Sunoo Park and Daniel R. Thomas (USENIX Security 2026) on how overbroad anti-hacking law chills good-faith security research — and why it names disclose.io as part of the fix. - [Policy Pulse - Issue #18 | Week of June 6, 2026](https://blog.disclose.io/policy-pulse-issue-18-week-of-june-6-2026.md) - Hackers on the Hill returns to DC on June 16, the first Capitol-side researcher-to-policymaker gathering of 2026. The White House signs the Mythos-era AI cybersecurity EO with a 30-day pre-release access window. A longer analysis lands later this week. - [Mark Your Calendar: The disclose.io Upcoming Dates Page Is Live](https://blog.disclose.io/mark-your-calendar-the-disclose-io-upcoming-dates-page-is-live.md) - The disclose.io Upcoming Dates page is now live — a shared community calendar tracking policy deadlines, regulations, CFPs, and legislation across the US, EU, UK, and Australia. Plus: show up at Hackers on the Hill, June 16. - [Policy Pulse - Issue #17 | Week of May 30, 2026](https://blog.disclose.io/policy-pulse-issue-17-week-of-may-30-2026.md) - Microsoft's MSRC invokes the Digital Crimes Unit against the Nightmare Eclipse zero-day drops, and the disclosure community is not having it. UK National Security Bill confirms CMA reform that protects roughly 300 researchers. - [Policy Pulse - Issue #16 | Week of May 23, 2026](https://blog.disclose.io/policy-pulse-issue-16-week-of-may-23-2026.md) - Peter G. Neumann, who moderated the ACM RISKS Forum for 41 years and helped found the discipline of secure-systems research, died May 17 at 93. CISA opens a public KEV nomination form. Cloudflare publishes its Project Glasswing post-mortem. - [Policy Pulse - Issue #15 | Week of May 16, 2026](https://blog.disclose.io/policy-pulse-issue-15-week-of-may-16-2026.md) - OpenAI launches Daybreak with 20+ vendor partners, putting a second restricted-access defensive AI consortium next to Anthropic's Glasswing. AISI says autonomous AI cyber capability is now doubling every 4.7 months. - [disclose.io/platforms: a community-maintained list of every bug bounty and VDP platform we know about](https://blog.disclose.io/disclose-io-platforms-a-community-maintained-list-of-every-bug-bounty-and-vdp-platform-we-know-about.md) - A single, canonical, community-maintained list of every bug bounty and vulnerability disclosure platform we know about — global, regional, and vertical-specific. Vendor-agnostic by design. - [Policy Pulse - Issue #14 | Week of May 9, 2026](https://blog.disclose.io/policy-pulse-issue-14-week-of-may-9-2026.md) - CAISI signs pre-deployment testing deals with Google, Microsoft, and xAI. CISA gives feds three days to patch Ivanti EPMM zero-day. NVD reclassifies 29,000 backlogged CVEs as Not Scheduled. - [Policy Pulse - Issue #13 | Week of May 3, 2026](https://blog.disclose.io/policy-pulse-issue-13-week-of-may-3-2026.md) - AISI's GPT-5.5 evaluation confirms frontier-model offensive cyber capability is a trend, not a Mythos one-off. NIST formally drops enrichment for 29,000 backlogged CVEs. UK still has no statutory defence. - [disclose.io/threats: documenting legal threats against security researchers](https://blog.disclose.io/disclose-io-threats-documenting-legal-threats-against-security-researchers.md) - A structured, public archive of legal threats, cease-and-desist letters, and prosecutions against security researchers engaged in good-faith vulnerability disclosure. The evidence base for policy reform. - [Policy Pulse - Issue #12 | Week of April 26, 2026](https://blog.disclose.io/policy-pulse-issue-12-week-of-april-26-2026.md) - CISA's KEV catalog absorbs 13 new CVEs in five days, the heaviest week since Emergency Directives retired in January. UK AISI publishes the first government evaluation of a frontier model's offensive cyber capabilities. - [The disclose.io Maturity Model: a six-level ladder for vulnerability disclosure programs](https://blog.disclose.io/the-disclose-io-maturity-model-a-six-level-ladder-for-vulnerability-disclosure-programs.md) - The disclose.io Maturity Model is a six-level ladder — from 'no contact' to 'full safe harbor with CVD' — that underpins every entry in the new directory. Here's how it works, and who it's for. - [Policy Pulse - Issue #11 | Week of April 19, 2026](https://blog.disclose.io/policy-pulse-issue-11-week-of-april-19-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. Top Story CIRCIA Final Rule on Collision Course with Funding Lapse as May 2026 Deadline Approaches CISA's Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) final rule, already dela… - [Introducing lookup.disclose.io: One Tool to Find All Security Contacts (Now in Beta)](https://blog.disclose.io/introducing-lookup-disclose-io-one-tool-to-find-all-security-contacts-now-in-beta.md) - Announcing lookup.disclose.io beta: universal security contact lookup for any digital asset. Find bug bounty programs, security.txt, and VDP contacts instantly. - [Policy Pulse - Issue #10 | Week of April 14, 2026](https://blog.disclose.io/policy-pulse-issue-10-week-of-april-14-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. - [Policy Pulse - Issue #9 | Week of April 6, 2026](https://blog.disclose.io/policy-pulse-issue-9-week-of-april-6-2026.md) - OWASP Agentic AI Top 10 redefines the disclosure landscape. Plus: OpenAI launches safety bug bounty, Langflow exploited in 20 hours, and GSA drops the first federal AI acquisition clause. - [Policy Pulse - Issue #8 | Week of March 29, 2026](https://blog.disclose.io/policy-pulse-issue-8-week-of-march-29-2026.md) - CVE program funding secured but transparency questions remain. Plus: lookup.disclose.io launches in beta, EU CRA countdown hits 6 months, and Rapid7 reports exploited vulns surged 105%. - [Policy Pulse - Issue #7 | Week of March 22, 2026](https://blog.disclose.io/policy-pulse-issue-7-week-of-march-22-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. - [Joining the Security Research Legal Defense Fund Board](https://blog.disclose.io/joining-the-security-research-legal-defense-fund-board.md) - Casey Ellis and Jen Ellis join the SRLDF board to strengthen legal defense for good-faith security researchers. Here's what it means and how you can help. - [Policy Pulse - Issue #6 | Week of March 15, 2026](https://blog.disclose.io/policy-pulse-issue-6-week-of-march-15-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. This week: White House Cyber Strategy, CVE program funding secured, UK Computer Misuse Act reform, EU CRA vulnerability guidance, and DHS shutdown delays CIRCIA. - [Policy Pulse - Issue #5 | Week of March 1, 2026](https://blog.disclose.io/policy-pulse-issue-5-week-of-march-1-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. This week: RUSI explores cyber deputisation and letters of marque, UK launches Cyber Essentials push, curl kills its bug bounty over AI slop, and the MITRE CVE contract enters its final two weeks. - [Policy Pulse - Issue #4 | Week of February 22, 2026](https://blog.disclose.io/policy-pulse-issue-4-week-of-february-22-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. This week: Australia mandates VDPs for all smart devices, MITRE CVE contract enters final countdown, and a researcher who found children's data exposed gets threatened with prosecution. - [Policy Pulse - Issue #3 | Week of February 15, 2026](https://blog.disclose.io/policy-pulse-issue-3-week-of-february-15-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. This week: CISA BOD 26-02 targets unsupported edge devices, MITRE CVE contract hits 30-day countdown, and UK CMA statutory defence takes shape. - [Modes of Public Vulnerability Disclosure: A 2026 Update](https://blog.disclose.io/modes-of-public-vulnerability-disclosure-a-2026-update.md) - Understanding the taxonomy of vulnerability disclosure—from private to full to coordinated—and why the industry has converged on 90 days as the rational baseline. Updated for 2026 with the latest from disclose.io Policymaker. - [Policy Pulse - Issue #2 | Week of February 8, 2026](https://blog.disclose.io/policy-pulse-issue-2-week-of-february-8-2026.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. - [Policy Pulse - Issue #1 | Week of February 1, 2026](https://blog.disclose.io/discloseio-policy-pulse-week-of-february.md) - Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research. - [Research on legal risk experiences — seeking interviewees](https://blog.disclose.io/research-on-legal-risk-experiences.md) - Academic research exploring the legal risks security researchers face when discovering and reporting vulnerabilities. If you've experienced legal threats or prosecution related to security research, your story could help shape better protections. - [The disclose.io Community Forum is Back—Here’s How to Dive In](https://blog.disclose.io/the-discloseio-community-forum-is-back.md) - The disclose.io community forum has been relaunched with new features for security researchers and organizations. Learn how to join the conversation, connect with fellow researchers, and contribute to safer vulnerability disclosure practices. - [Bill Proposal: Unpacking the Cyber Conspiracy Modernization Act](https://blog.disclose.io/bill-proposal-unpacking-the-cyber.md) - The Cybercrime Conspiracy Modernization Act (CCMA), introduced by Senators Mike Rounds (R-SD) and Kirsten Gillibrand (D-NY), proposes amendments to the Computer Fraud and Abuse Act (CFAA) to establish specific penalties for conspiracy to commit cybercrimes and to enhance existing punishments for of… - [A brief history of vulnerability disclosure and bug bounty](https://blog.disclose.io/a-brief-history-of-vulnerability-disclosure-and-bug-bounty.md) - Explore the evolution of vulnerability disclosure from the early days of full disclosure debates through the emergence of bug bounty programs. A comprehensive three-part series by Dennis Fisher covering the history that shaped modern security research. - [Introducing the disclose.io Policymaker!](https://blog.disclose.io/introducing-the-discloseio-policymaker.md) - Introducing the disclose.io Policymaker tool — a free, open-source generator for creating vulnerability disclosure policies. Build compliant VDP and bug bounty policies in minutes with our guided policy builder. - [Make DMCA About Copyright Again](https://blog.disclose.io/make-dmca-about-copyright-again.md) - The DMCA's anti-circumvention provisions have been misused against security researchers for decades. Here's why we need to return the Digital Millennium Copyright Act to its original purpose and protect good-faith security research. - [VIDEO: An intro to disclose.io and hacker safety](https://blog.disclose.io/video-an-intro-to-discloseio-and-hacker-safety.md) - Watch this introductory video explaining what disclose.io does, why hacker safety matters, and how organizations can implement vulnerability disclosure programs that protect both researchers and their systems. - [dnssecuritytxt](https://blog.disclose.io/dnssecuritytxt.md) - DNS-based discovery of security.txt files using the _securitytxt TXT record. Learn how dnssecuritytxt enables organizations to publish vulnerability disclosure contact information through DNS, complementing the traditional .well-known/security.txt approach. - [Establishing asset ownership in vulnerability reporting](https://blog.disclose.io/establishing-asset-ownership-in-vulnerability-reporting.md) - How do you verify who actually owns an asset when reporting a vulnerability? This guide covers techniques for establishing asset ownership, avoiding reporting to the wrong party, and ensuring your security research reaches the right people. - [Request For Comment: dioterms open-source VDP policy](https://blog.disclose.io/request-for-comment-dioterms-open-source-vdp-policy.md) - Request for comment on dioterms, the disclose.io open-source vulnerability disclosure policy template. Help shape the future of standardized VDP language by providing feedback on safe harbor provisions and researcher protections. - [2020: A Good Year for Hackers](https://blog.disclose.io/2020-a-good-year-for-hackers.md) - A look back at 2020's major wins for the security research community — from CFAA reform progress to expanded safe harbor provisions. How the year shaped the future of ethical hacking and vulnerability disclosure. ## Optional - [RSS Feed](https://blog.disclose.io/rss/) - [Sitemap](https://blog.disclose.io/sitemap.xml) - [Full content of pages and posts](https://blog.disclose.io/llms-full.txt)