How we publish security advisories
This feed carries security advisories and incident notices for the CyberOptix CTEM Platform. It is deliberately separate from Release notes, and has its own RSS feed, so subscribing to advisories does not subscribe you to the changelog.
What you can expect here
Advisories for vulnerabilities in the platform that reached a release, whether we found them or you did, with affected versions, severity, and what you need to do.
Incident notices for security incidents affecting the service, published after resolution.
Severity uses the same five-level scale as findings in the product, so a High here means what a High means everywhere else. Publication is timed to a fix being available rather than deployed everywhere, because there may be something for you to do.
The full detail - what gets a bulletin, target timelines per severity, what a bulletin contains - is in the security bulletin policy.
About an empty feed
If you check back and nothing has been published, that means no advisories met the policy's criteria in that period. It does not mean nothing was found.
We say so explicitly because a quiet advisory feed is easy to read as an absence of diligence, and because a policy describing only what happens when something is found tells you nothing about the other case.
Reporting something to us
If you believe you have found a vulnerability in the platform, contact [email protected].
Please give us a reasonable period to investigate and fix before disclosing publicly. We will keep you informed, and we will credit you in the bulletin unless you would rather we did not.
If you need this for an audit
The policy page plus this feed is our vulnerability
communication process, in public, with no request required. The equivalent for change
communication is the release note policy and
/release-notes/manifest.json.