@calle No one ever said you disclosed which projects you scan. @aljaz was simply saying to stop signaling that you're finding critical vulns because this can act as an incentive for ill-intended hackers. You're basically putting extra pressure on the red team by saying "we've found bugs".

Replies (4)

I would argue that it does. It shifts from "is there a needle in the haystack?" To: "there is one.... In EACH haystack". Basically putting them in active search mode.
โ†‘