Press Release

Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again

Sophia Antipolis, France, August 7th, 2026, CyberNewswire

At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as endrazine, announced the rebirth of the original Bugtraq mailing list.

Established in 1993, Bugtraq is the original mailing list where cybersecurity vulnerabilities, mitigations, and cutting-edge techniques have been discussed at scale.

With over 120,000 references from the NVD/CVE database, Bugtraq and its associated website securityfocus.com are a pillar of modern information security, providing moderated, quality information to Product Security teams and the larger infosec community, free of charge.

For roughly a third of all catalogued vulnerabilities, SecurityFocus remains a primary technical reference.

In a time where cybersecurity information fades into oblivion, between ephemeral social media posts, paywalls, gated information, or dead links, providing a place where security researchers may share their work and have it archived for posterity is of prime importance to the cybersecurity community.

Bugtraq is a community service and an open platform available to all security researchers. There is no paywall, no gated access, no commercial agenda. The list exists to serve the cybersecurity community.

“At the end of the day, Bugtraq is what its users make of it,” said Jonathan Brossard, adding: “We are providing the platform. The community decides what it becomes.”

To this end, SecurityFocus features two lists:

DEF CON founder Jeff Moss welcomed the relaunch in a public post to the list: “I believe the bug belongs to the finder and hopefully this can become a neutral place to discuss them.”

Subscriptions and archives are available at https://securityfocus.com and https://bugtraq.ai.

We would like to express our gratitude to past moderators — legendary and anonymous alike for their community service, running a mailing list that is a tremendous source of information, on a daily basis. You shaped the field of information security.

We would finally like to express our gratitude to Solar Designer for preserving the archives of Bugtraq. For this, and countless other accomplishments, you are a legend.

Call for Volunteers: Seeking Moderators to Help Steer the Community

Should you have experience in moderating full disclosure mailing lists, time to contribute, and a desire to help the community, interested parties feel free to reach out.

About Bugtraq

Founded in 1993, Bugtraq is one of the longest-running cybersecurity mailing lists. For over two decades it served as the primary channel for vulnerability disclosure, security advisories, and original research. The list is now independently operated and hosted at securityfocus.com.

Contact

Security Researcher

Jonathan BROSSARD

MOABI Solutions

endrazine@psirt.com

Kavichselvan

Kavichselvan is a Cybersecurity Enthusiast and Journalist covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago