Responsible Disclosure
How to report a security issue in this site.
If you have found a security issue on this site, thank you โ please send a
confidential, plain-text description to mailto:flagon_plazas0x@icloud.com. Reports are
handled personally; there is no bug-bounty programme, no financial reward, and
no public acknowledgement unless you ask for one.
What is in scope
This is a static publishing site (daily/monthly cyber-intelligence digests, a story database, a wiki and a 3D incident globe) built from public sources. Realistic in-scope findings include:
- Stored or reflected cross-site scripting, broken access control, or injection in the client-side app pages (story database, globe, flashcards, CVE matrix).
- Malicious or self-XSS vectors that could affect a reader.
- Supply-chain / dependency integrity gaps in the site's bundled scripts.
- Misconfigurations allowing content tampering or credential exposure in the hosting or publishing accounts that feed this site.
Out of scope (by design)
- Provider-managed infrastructure: the site is hosted on GitHub Pages (to be fronted by Cloudflare). TLS config, edge security headers and platform access control are the provider's responsibility, not a vulnerability of this project.
- Phishing, spam, or abuse of the domain about the site (report those to the registrar / mailbox provider).
- Any issue involving attack of this site's readers or of third-party systems.
- Self-XSS (pasting into your own browser), or issues requiring the victim to disable security controls.
- Rate-limiting or denial-of-service findings against a static CDN.
What we promise
- We will acknowledge receipt within 7 days and aim for a first response with a disposition (accepted / wontfix / needs-verification) within 30 days.
- We will not pursue legal action against good-faith researchers acting within these scope rules and not causing harm.
- We ask that you give us a reasonable window to fix and publish before public disclosure, and that you avoid actions that disrupt the site or other users.
OPSEC note
This site names threat actors and incident victims. A few things are fixed policy and do not constitute a vulnerability to report: incident summaries link to their public sources, only publicly-reported facts are reproduced, and PII is never unnecessarily included. Constructive review of the fact-checking pipeline is welcome at the same contact.