Skip to main content

How we publish security advisories

This feed carries security advisories and incident notices for the CyberOptix CTEM Platform. It is deliberately separate from Release notes, and has its own RSS feed, so subscribing to advisories does not subscribe you to the changelog.

What you can expect here​

Advisories for vulnerabilities in the platform that reached a release, whether we found them or you did, with affected versions, severity, and what you need to do.

Incident notices for security incidents affecting the service, published after resolution.

Severity uses the same five-level scale as findings in the product, so a High here means what a High means everywhere else. Publication is timed to a fix being available rather than deployed everywhere, because there may be something for you to do.

The full detail - what gets a bulletin, target timelines per severity, what a bulletin contains - is in the security bulletin policy.

About an empty feed​

If you check back and nothing has been published, that means no advisories met the policy's criteria in that period. It does not mean nothing was found.

We say so explicitly because a quiet advisory feed is easy to read as an absence of diligence, and because a policy describing only what happens when something is found tells you nothing about the other case.

Reporting something to us​

If you believe you have found a vulnerability in the platform, contact [email protected].

Please give us a reasonable period to investigate and fix before disclosing publicly. We will keep you informed, and we will credit you in the bulletin unless you would rather we did not.

If you need this for an audit​

The policy page plus this feed is our vulnerability communication process, in public, with no request required. The equivalent for change communication is the release note policy and /release-notes/manifest.json.