<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://docs.cyberoptix.io/security-bulletins</id>
    <title>Security bulletins</title>
    <updated>2026-09-24T00:00:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://docs.cyberoptix.io/security-bulletins"/>
    <subtitle>Security advisories and incident notices.</subtitle>
    <icon>https://docs.cyberoptix.io/img/favicon.png</icon>
    <rights>Copyright © 2026</rights>
    <entry>
        <title type="html"><![CDATA[How we publish security advisories]]></title>
        <id>https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins</id>
        <link href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins"/>
        <updated>2026-09-24T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[The bulletin feed, what gets one, and how to report something to us.]]></summary>
        <content type="html"><![CDATA[<p>This feed carries security advisories and incident notices for the <!-- -->CyberOptix CTEM Platform<!-- -->. It is
deliberately separate from <a class="" href="https://docs.cyberoptix.io/release-notes">Release notes</a>, and has its own RSS feed, so
subscribing to advisories does not subscribe you to the changelog.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-can-expect-here">What you can expect here<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#what-you-can-expect-here" class="hash-link" aria-label="Direct link to What you can expect here" title="Direct link to What you can expect here" translate="no">​</a></h2>
<p><strong>Advisories</strong> for vulnerabilities in the platform that reached a release, whether we
found them or you did, with affected versions, severity, and what you need to do.</p>
<p><strong>Incident notices</strong> for security incidents affecting the service, published after
resolution.</p>
<p>Severity uses the same five-level scale as findings in the product, so a High here means
what a High means everywhere else. Publication is timed to a fix being <em>available</em> rather
than deployed everywhere, because there may be something for you to do.</p>
<p>The full detail - what gets a bulletin, target timelines per severity, what a bulletin
contains - is in the <a class="" href="https://docs.cyberoptix.io/policies/security-bulletins">security bulletin policy</a>.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="about-an-empty-feed">About an empty feed<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#about-an-empty-feed" class="hash-link" aria-label="Direct link to About an empty feed" title="Direct link to About an empty feed" translate="no">​</a></h2>
<p>If you check back and nothing has been published, that means no advisories met the
policy's criteria in that period. It does not mean nothing was found.</p>
<p>We say so explicitly because a quiet advisory feed is easy to read as an absence of
diligence, and because a policy describing only what happens when something <em>is</em> found
tells you nothing about the other case.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting-something-to-us">Reporting something to us<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#reporting-something-to-us" class="hash-link" aria-label="Direct link to Reporting something to us" title="Direct link to Reporting something to us" translate="no">​</a></h2>
<p>If you believe you have found a vulnerability in the platform, contact
<a href="mailto:support@purpleteamsoftware.com" target="_blank" rel="noopener noreferrer" class="">support@purpleteamsoftware.com</a>.</p>
<p>Please give us a reasonable period to investigate and fix before disclosing publicly. We
will keep you informed, and we will credit you in the bulletin unless you would rather we
did not.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="if-you-need-this-for-an-audit">If you need this for an audit<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#if-you-need-this-for-an-audit" class="hash-link" aria-label="Direct link to If you need this for an audit" title="Direct link to If you need this for an audit" translate="no">​</a></h2>
<p>The <a class="" href="https://docs.cyberoptix.io/policies/security-bulletins">policy page</a> plus this feed is our vulnerability
communication process, in public, with no request required. The equivalent for change
communication is the <a class="" href="https://docs.cyberoptix.io/policies/release-notes">release note policy</a> and
<a href="https://docs.cyberoptix.io/release-notes/manifest.json" target="_blank" rel="noopener noreferrer" class=""><code>/release-notes/manifest.json</code></a>.</p>]]></content>
        <category label="announcement" term="announcement"/>
    </entry>
</feed>