Recent guidance establishes best practices for development of coordinated vulnerability disclosure (CVD) programs. This comes as both public and private organizations are grappling with the prospect of near-term "machine speed" discovery of vulnerabilities by attackers wielding AI tools, and looking at potential major overhauls to their remediation and reporting processes.




