the 90 day disclosure policy is dead :: Himanshu Anand :: Threat Notes
Posted by jpluimers on 2026/05/19
15 minute important read: [Wayback/Archive] the 90 day disclosure policy is dead :: Himanshu Anand :: Threat Notes
TL;DR: (not sugar coated; read the full post and their follow-ups on the why and how)
- Treat every critical security issue as P0 and fix it immediately.
- Integrate LLMs at the point of code push.
Via [Wayback/Archive] Dr. Christopher Kunz: “@Lilith (Original: “the patch diff is the signal.”, via https://blog.himanshuanand.com/2026/05…/the-90-day-disclosure-policy-is-dead/) …” – chaos.social
and last week’s [Wayback/Archive] Is the 90-Day Disclosure Window Dead? How AI is Rewriting the Rules of CVD | CVD Portal Blog – CVD Portal
--jeroen






Leave a comment