CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers — Threadlinqs Intelligence
As of 2026-07-16, CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers is a info-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1419 · Severity: INFO · Status: ACTIVE · Category: THREAT_INTEL
On July 15, 2026, CISA and four allied national cyber authorities (US NSA, Japan's JPCERT/CC, the Netherlands' NCSC-NL, and the UK's NCSC) jointly published guidance urging software manufacturers and
CISA, in partnership with the U.S. National Security Agency (NSA), Japan Computer Emergency Response Team Coordination Center (JPCERT/CC), the Netherlands' National Cyber Security Centre (NCSC-NL), and the UK's National Cyber Security Centre (NCSC-UK), published "Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers" on July 15, 2026. The guidance targets the full CVD operational chain: receiving vulnerability reports, communicating with researchers, triaging findings, developing fixes, coordinating disclosure timing, and assigning CVE identifiers. Concrete recommendations include publishing an RFC 9116-compliant security.txt file with machine- and human-readable researcher contact information; acknowledging researcher outreach within 2-3 business days; offering explicit safe-harbor assurances that good-faith testing will not be treated as unauthorized access under laws such as the U.S. Computer Fraud and Abuse Act; setting the widest reasonable testing scope; separating vulnerability-disclosure intake from general customer support so reports are not lost in unrelated ticket queues; issuing CVE identifiers for internally discovered vulnerabilities and not just externally reported ones; publishing advisories via the Common Security Advisory Framework (CSAF) and never paywalling them; avoiding blanket non-disclosure agreements or silent, undocumented fixes; and, on the remediation side, prioritizing fixes by exploitability and real attack-path viability rather than CVSS severity scores alone, validating compensating controls when patches are not yet available, and verifying that remediation actually eliminates the exploitable attack path rather than merely confirming a patch was applied. CISA framed the guidance as an extension of its Secure by Design initiative, which pushes technology providers to take greater ownership of vulnerability identification and remediation rather than externalizing that cost to customers and researchers.
The guidance's timing and framing are directly informed by an incident involving CISA itself. A GitHub account, created in approximately September 2018, was used by CISA contractor Nightwing (a government contractor based in Dulles, Virginia) to host a public repository named "Private-CISA," established/exposed on November 13, 2025 and left public for roughly six months. The repository contained approximately 844 MB of internal data, including Kubernetes configuration files, GitHub Actions workflows, internal documentation backups, SSH keys, tokens, and configuration files. Two files were particularly sensitive: "importantAWStokens," containing administrative credentials for three AWS GovCloud servers, and "AWS-Workspace-Firefox-Passwords.csv," a plaintext list of usernames and passwords for numerous internal CISA systems, including CISA's internal "artifactory" code-package repository and the "LZ-DSO" (Landing Zone DevSecOps) environment. Many of the exposed plaintext passwords followed a weak, predictable convention combining a platform name with the current year. Commit history reviewed by GitGuardian researcher Guillaume Valadon showed the contractor operator had deliberately disabled GitHub's built-in secret-scanning/push-protection feature, the default guardrail that blocks publication of recognizable credential patterns, prior to committing the credential files. GitGuardian's automated scanner sent nine alerts about the exposure prior to May 15, 2026, none of which drew a response from CISA or Nightwing; Valadon then escalated directly and separately notified journalist Brian Krebs of KrebsOnSecurity. Independently, researcher Philippe Caturegli of Seralys validated that the exposed AWS credentials were still live. The repository was taken offline shortly after the escalation/notification (reported as roughly 26 hours), but the exposed AWS GovCloud keys remained valid for an additional 48+ hours before rotation completed, reflecting difficulty rotating
Weaknesses (CWE)
CWE-798, CWE-312, CWE-522, CWE-521, CWE-668
Target sectors: government administration, software-vendors, critical-infrastructure
Target regions: united states of america, united kingdom, netherlands, japan, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, INFO, threat intelligence, cybersecurity, T1593.003, T1583.006, T1078.004, T1199, T1078.004, T1078.004, T1078.004, T1562.001, T1552.001, T1552.004