Desk live·
ForensicPost
Cloud/Method/File 26-0323

Coordinated Disclosure Breaks Down at Tens of Thousands of Findings

Coordinated disclosure assumes a small number of findings, each with a maintainer able to act inside the window. Neither assumption survives discovery at tens of thousands per month.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetDisclosure governance
ActorUnattributed
S. Rosler12 min readConfidence: medium2 sources reviewed

The ninety-day coordinated disclosure norm is one of the more successful pieces of informal governance in security. A researcher reports privately, the maintainer has ninety days, and publication follows regardless — the deadline being what converts a report into action.

It works because of assumptions that are rarely stated: findings arrive at a rate maintainers can absorb, each has a responsible party, and the threat of publication is a proportionate lever.

Volume Breaks The Lever

A deadline is meaningful when meeting it is possible. A maintainer receiving forty findings at once cannot triage them in ninety days, and the deadline stops being an incentive and becomes a countdown to mass publication.

The six per cent remediation rate at 26-0410 is what that looks like in practice. The mechanism designed to compel fixes is now generating public disclosures of unfixed defects at scale.

Aggregate Risk Has No Place In The Model

Coordinated disclosure treats each vulnerability independently. Publishing one flaw in one library is a bounded event.

Publishing several thousand across foundational libraries simultaneously is not a series of bounded events. It is a change in the aggregate exploitability of the software estate, and no current framework asks anyone to assess that before the clock runs out.

What A Revised Model Would Need

Analysts working on this have converged on similar components: disclosure sequencing prioritised by real-world exposure rather than submission order, timelines that account for maintainer capacity rather than assuming it, and some assessment of aggregate risk before bulk publication.

Each of those weakens the deadline that made coordinated disclosure work. That is the genuine tension, and nobody has resolved it — the alternative to a hard deadline has historically been indefinite delay, which is how the norm arose in the first place.

How we reported this

This is a standards file compiled from published research and analysis, listed below. The characterisation of the tension is ours and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. Project Glasswing and the AI vulnerability disclosure velocity crisisCloud Security Alliance
  2. When AI becomes the attacker: Project Glasswing and the autonomous zero-day eraCloud Security Alliance
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary