<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Security bulletins</title>
        <link>https://docs.cyberoptix.io/security-bulletins</link>
        <description>Security advisories and incident notices.</description>
        <lastBuildDate>Thu, 24 Sep 2026 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <copyright>Copyright © 2026</copyright>
        <item>
            <title><![CDATA[How we publish security advisories]]></title>
            <link>https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins</link>
            <guid>https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins</guid>
            <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The bulletin feed, what gets one, and how to report something to us.]]></description>
            <content:encoded><![CDATA[<p>This feed carries security advisories and incident notices for the <!-- -->CyberOptix CTEM Platform<!-- -->. It is
deliberately separate from <a class="" href="https://docs.cyberoptix.io/release-notes">Release notes</a>, and has its own RSS feed, so
subscribing to advisories does not subscribe you to the changelog.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-can-expect-here">What you can expect here<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#what-you-can-expect-here" class="hash-link" aria-label="Direct link to What you can expect here" title="Direct link to What you can expect here" translate="no">​</a></h2>
<p><strong>Advisories</strong> for vulnerabilities in the platform that reached a release, whether we
found them or you did, with affected versions, severity, and what you need to do.</p>
<p><strong>Incident notices</strong> for security incidents affecting the service, published after
resolution.</p>
<p>Severity uses the same five-level scale as findings in the product, so a High here means
what a High means everywhere else. Publication is timed to a fix being <em>available</em> rather
than deployed everywhere, because there may be something for you to do.</p>
<p>The full detail - what gets a bulletin, target timelines per severity, what a bulletin
contains - is in the <a class="" href="https://docs.cyberoptix.io/policies/security-bulletins">security bulletin policy</a>.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="about-an-empty-feed">About an empty feed<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#about-an-empty-feed" class="hash-link" aria-label="Direct link to About an empty feed" title="Direct link to About an empty feed" translate="no">​</a></h2>
<p>If you check back and nothing has been published, that means no advisories met the
policy's criteria in that period. It does not mean nothing was found.</p>
<p>We say so explicitly because a quiet advisory feed is easy to read as an absence of
diligence, and because a policy describing only what happens when something <em>is</em> found
tells you nothing about the other case.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting-something-to-us">Reporting something to us<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#reporting-something-to-us" class="hash-link" aria-label="Direct link to Reporting something to us" title="Direct link to Reporting something to us" translate="no">​</a></h2>
<p>If you believe you have found a vulnerability in the platform, contact
<a href="mailto:support@purpleteamsoftware.com" target="_blank" rel="noopener noreferrer" class="">support@purpleteamsoftware.com</a>.</p>
<p>Please give us a reasonable period to investigate and fix before disclosing publicly. We
will keep you informed, and we will credit you in the bulletin unless you would rather we
did not.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="if-you-need-this-for-an-audit">If you need this for an audit<a href="https://docs.cyberoptix.io/security-bulletins/2026/09/24/publishing-security-bulletins#if-you-need-this-for-an-audit" class="hash-link" aria-label="Direct link to If you need this for an audit" title="Direct link to If you need this for an audit" translate="no">​</a></h2>
<p>The <a class="" href="https://docs.cyberoptix.io/policies/security-bulletins">policy page</a> plus this feed is our vulnerability
communication process, in public, with no request required. The equivalent for change
communication is the <a class="" href="https://docs.cyberoptix.io/policies/release-notes">release note policy</a> and
<a href="https://docs.cyberoptix.io/release-notes/manifest.json" target="_blank" rel="noopener noreferrer" class=""><code>/release-notes/manifest.json</code></a>.</p>]]></content:encoded>
            <category>announcement</category>
        </item>
    </channel>
</rss>