WE ARE BACK.

bugtraq@securityfocus.com — est. 1993

Bugtraq was the security community's mailing list. Founded in 1993 by Scott Chasin, it became the primary channel for vulnerability disclosure, security advisories, and original research for over two decades. When it mattered, it was on Bugtraq.

After Symantec's acquisition of SecurityFocus in 2002, the list slowly declined. Broadcom stopped updating the BID database in 2019. Accenture acquired the remains in 2020, tried to shut Bugtraq down, reversed course under community pressure, then went permanently silent. The last message was posted January 17, 2021.

SecurityFocus is now under independent, community stewardship. Bugtraq is live again — curated, moderated, and open to submissions from security researchers worldwide. We're also launching a second list dedicated to vulnerability research in AI and machine learning systems.

The historical Bugtraq archives are preserved by MARC (1993–2021) and Openwall (2003–2021).

Mailing Lists

Bugtraq

bugtraq@securityfocus.com

Curated vulnerability disclosure and security advisory mailing list. All targets — proprietary, open source, hardware, firmware, embedded. Moderated for quality. The continuation of the original Bugtraq.

Bugtraq AI

bugtraq@bugtraq.ai

Vulnerability disclosures and security research focused on AI/ML systems — model exploits, inference attacks, training data poisoning, framework vulnerabilities, and adversarial machine learning.