CISA, the NSA, and international partners published joint guidance urging software manufacturers and online service providers to formalize coordinated vulnerability disclosure (CVD) programs for working with external security researchers. The guidance calls for organizations to publish a clear vulnerability disclosure policy, define internal processes for receiving, triaging, remediating, and disclosing reported flaws, and assign CVE identifiers where appropriate to improve tracking and transparency.
The document also recommends using third-party coordinators such as CISA or national CSIRTs when organizations need support handling disclosures, and it highlights safe harbor language to protect good-faith researchers from legal action. CISA said the practices can help vendors strengthen product security and give customers and critical infrastructure operators a way to assess a supplier’s maturity in handling vulnerability reports and remediation.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
CISA, the NSA, and international partners published joint guidance on establishing coordinated vulnerability disclosure programs for software manufacturers and online service providers. The guidance recommends a public vulnerability disclosure policy, triage and remediation processes, CVE assignment, use of third-party coordinators, and safe harbor language for good-faith researchers.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
waterisac.org
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.