Cybersecurity 3 min agoAdd to bookmarks

Bugtraq - the reference mailing list for the security community since 1993 - has just relaunched on SecurityFocus. An unexpected resurrection for a channel that has trained generations of vulnerability researchers.
Bugtraq is one of the oldest and most influential vulnerability disclosure mailing lists in the world. Created in 1993 by Scott Chasin, it was for over a decade the go-to channel for publishing CVEs (before the term was standardized), exploits, and security analyses. Researchers like Bruce Schneier, Dan Kaminsky, and Solar Designer published some of their most notable work there.
SecurityFocus acquired and hosted Bugtraq until its takeover by Symantec (2002), after which the channel gradually lost its prominence with the rise of official CVE databases, vendor advisories, GitHub, and Twitter as alternative vectors. The list fell into a long dormancy.
According to an announcement published on lists.securityfocus.com and spotted on Hacker News on August 5, 2026, Bugtraq is officially back with a new moderation team. The format remains that of a classic mailing list—email subscription, public archives, open submissions.
The announcement does not provide details on governance changes or potential sponsors, but the technical platform (Hyperkitty) is the same as that used by the Linux Foundation’s mailing lists and other major open-source projects.
The news may seem trivial in an era dominated by NVD, OSV, GitHub Security Advisories, CISA advisories, and dozens of specialized feeds. Yet Bugtraq offers something these tools lack: a culture of direct, unfiltered disclosure, bypassing vendor mediation.
The coordinated disclosure (or responsible disclosure) model has its merits, but it also has blind spots—especially when vendors take months to patch a known flaw. Bugtraq was a last-resort recourse for researchers, and that mechanism may still be useful.
The open question: In an environment where LinkedIn and X/Twitter have largely replaced mailing lists for rapid information sharing, what will the actual audience be for this revival? Bugtraq’s historical archive remains a valuable resource for researchers—perhaps the main argument for its relaunch.
Over 100,000 messages archived between 1993 and the 2010s. Some of the most critical vulnerabilities in history (Windows NT flaws, early Apache exploits, SSH/SSL discoveries) were announced on Bugtraq before receiving a CVE.
What to do now: If you're a security researcher or threat intelligence professional, consider subscribing to the list at lists.securityfocus.com to monitor early-stage disclosures that may not yet have an assigned CVE.
Article produced by artificial intelligence, reviewed under human editorial control.