Bugtraq is back: the legendary security mailing list returns to SecurityFocus

Cybersecurity 3 min agoAdd to bookmarks

Bugtraq is back: the legendary security mailing list returns to SecurityFocus
Illustration : Momiji Shirogane

Bugtraq - the reference mailing list for the security community since 1993 - has just relaunched on SecurityFocus. An unexpected resurrection for a channel that has trained generations of vulnerability researchers.

What is Bugtraq?

Bugtraq is one of the oldest and most influential vulnerability disclosure mailing lists in the world. Created in 1993 by Scott Chasin, it was for over a decade the go-to channel for publishing CVEs (before the term was standardized), exploits, and security analyses. Researchers like Bruce Schneier, Dan Kaminsky, and Solar Designer published some of their most notable work there.

SecurityFocus acquired and hosted Bugtraq until its takeover by Symantec (2002), after which the channel gradually lost its prominence with the rise of official CVE databases, vendor advisories, GitHub, and Twitter as alternative vectors. The list fell into a long dormancy.

The Comeback

According to an announcement published on lists.securityfocus.com and spotted on Hacker News on August 5, 2026, Bugtraq is officially back with a new moderation team. The format remains that of a classic mailing list—email subscription, public archives, open submissions.

The announcement does not provide details on governance changes or potential sponsors, but the technical platform (Hyperkitty) is the same as that used by the Linux Foundation’s mailing lists and other major open-source projects.

Why This Matters in 2026

The news may seem trivial in an era dominated by NVD, OSV, GitHub Security Advisories, CISA advisories, and dozens of specialized feeds. Yet Bugtraq offers something these tools lack: a culture of direct, unfiltered disclosure, bypassing vendor mediation.

The coordinated disclosure (or responsible disclosure) model has its merits, but it also has blind spots—especially when vendors take months to patch a known flaw. Bugtraq was a last-resort recourse for researchers, and that mechanism may still be useful.

The open question: In an environment where LinkedIn and X/Twitter have largely replaced mailing lists for rapid information sharing, what will the actual audience be for this revival? Bugtraq’s historical archive remains a valuable resource for researchers—perhaps the main argument for its relaunch.

Bugtraq by the Numbers

Over 100,000 messages archived between 1993 and the 2010s. Some of the most critical vulnerabilities in history (Windows NT flaws, early Apache exploits, SSH/SSL discoveries) were announced on Bugtraq before receiving a CVE.

What to do now: If you're a security researcher or threat intelligence professional, consider subscribing to the list at lists.securityfocus.com to monitor early-stage disclosures that may not yet have an assigned CVE.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

17 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information