{
    "version": "https://jsonfeed.org/version/1",
    "title": "Security bulletins",
    "home_page_url": "https://docs.cyberoptix.io/security-bulletins",
    "description": "Security advisories and incident notices.",
    "items": [
        {
            "id": "https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins",
            "content_html": "<p>This feed carries security advisories and incident notices for the <!-- -->CyberOptix CTEM Platform<!-- -->. It is\ndeliberately separate from <a class=\"\" href=\"https://docs.cyberoptix.io/release-notes\">Release notes</a>, and has its own RSS feed, so\nsubscribing to advisories does not subscribe you to the changelog.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"what-you-can-expect-here\">What you can expect here<a href=\"https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#what-you-can-expect-here\" class=\"hash-link\" aria-label=\"Direct link to What you can expect here\" title=\"Direct link to What you can expect here\" translate=\"no\">​</a></h2>\n<p><strong>Advisories</strong> for vulnerabilities in the platform that reached a release, whether we\nfound them or you did, with affected versions, severity, and what you need to do.</p>\n<p><strong>Incident notices</strong> for security incidents affecting the service, published after\nresolution.</p>\n<p>Severity uses the same five-level scale as findings in the product, so a High here means\nwhat a High means everywhere else. Publication is timed to a fix being <em>available</em> rather\nthan deployed everywhere, because there may be something for you to do.</p>\n<p>The full detail - what gets a bulletin, target timelines per severity, what a bulletin\ncontains - is in the <a class=\"\" href=\"https://docs.cyberoptix.io/policies/security-bulletins\">security bulletin policy</a>.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"about-an-empty-feed\">About an empty feed<a href=\"https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#about-an-empty-feed\" class=\"hash-link\" aria-label=\"Direct link to About an empty feed\" title=\"Direct link to About an empty feed\" translate=\"no\">​</a></h2>\n<p>If you check back and nothing has been published, that means no advisories met the\npolicy's criteria in that period. It does not mean nothing was found.</p>\n<p>We say so explicitly because a quiet advisory feed is easy to read as an absence of\ndiligence, and because a policy describing only what happens when something <em>is</em> found\ntells you nothing about the other case.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"reporting-something-to-us\">Reporting something to us<a href=\"https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#reporting-something-to-us\" class=\"hash-link\" aria-label=\"Direct link to Reporting something to us\" title=\"Direct link to Reporting something to us\" translate=\"no\">​</a></h2>\n<p>If you believe you have found a vulnerability in the platform, contact\n<a href=\"mailto:support@purpleteamsoftware.com\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">support@purpleteamsoftware.com</a>.</p>\n<p>Please give us a reasonable period to investigate and fix before disclosing publicly. We\nwill keep you informed, and we will credit you in the bulletin unless you would rather we\ndid not.</p>\n<h2 class=\"anchor anchorTargetStickyNavbar_Vzrq\" id=\"if-you-need-this-for-an-audit\">If you need this for an audit<a href=\"https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#if-you-need-this-for-an-audit\" class=\"hash-link\" aria-label=\"Direct link to If you need this for an audit\" title=\"Direct link to If you need this for an audit\" translate=\"no\">​</a></h2>\n<p>The <a class=\"\" href=\"https://docs.cyberoptix.io/policies/security-bulletins\">policy page</a> plus this feed is our vulnerability\ncommunication process, in public, with no request required. The equivalent for change\ncommunication is the <a class=\"\" href=\"https://docs.cyberoptix.io/policies/release-notes\">release note policy</a> and\n<a href=\"https://docs.cyberoptix.io/release-notes/manifest.json\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\"><code>/release-notes/manifest.json</code></a>.</p>",
            "url": "https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins",
            "title": "How we publish security advisories",
            "summary": "The bulletin feed, what gets one, and how to report something to us.",
            "date_modified": "2026-09-24T00:00:00.000Z",
            "tags": [
                "announcement"
            ]
        }
    ]
}