This is probably the best public Vulnerability Disclosure Program terms I've ever seen. It demonstrates the exact nature of a VDP, "see something, say something" no more, no less. +10 for hosting a @securitytxt file too. Nice work @ServiceNow 👏
Looking for a little project to keep you busy on the weekend? I was just thinking: how many of the breached websites in @haveibeenpwned now have a security.txt file? So, if you feel like grabbing those domains and querying them all, there's an API here: https://t.co/ftiKkfH7Hp
This is great: having a security.txt file is now mandatory for Dutch government websites. They either need to apply this as a standard or provide a good justification for why they're not using it ("Apply of Explain") https://t.co/Q99eDiR1AW
security.txt 📑 has been added to the 'Comply or Explain' list of the Netherlands Standardisation Forum. This means that Dutch municipalities, provinces, the state, water boards and all operational organisations are obliged to apply this open standard.✅https://t.co/LPeSFMmQAc
Bridge the gap between your website and security researchers. ✅ Implement security.txt and promote coordinated vulnerability disclosure.
Need help getting started?
➡️ Head on over to https://t.co/cVAwRS9qdi.
#securitytxt#cybersecurity
Can you spare an hour to help us improve https://t.co/G5RrCkieuU (the official home of RFCs)? If you’ve used RFCs for work, school or research, we’d love to learn from you - particularly if you're new here! Volunteer by answering a few quick questions: https://t.co/ifQZAe0OQU
A tale of Google dorks finding subdomain takeovers plus why having a security.txt & a responsive security team are good news all round. London Councils & pirate books. Google dorking for subdomain takeovers. Thanks to our @OPSEC_failed
https://t.co/msCkRLzeZQ
#cybersecuritytips
Check out the just released fresh version of https://t.co/brl6s4Llhm with improved tests for CSP and security.txt, https://t.co/kWnTE39dX4
Happy testing and improving!
#moderninternet