Lancope presents joint research at Virus Bulletin in Berlin

Best practices for disclosure of vulnerability exploitation

Lancope, Inc., a leader in network visibility and security intelligence, presented with Microsoft at Virus Bulletin 2013 in Berlin, Germany on Wednesday, October 2. Lancope’s Director of Security Research, Tom Cross, co-presented a session with Holly Stewart, Sr. Program Manager Lead at Microsoft Malware Protection Center, covering best practices for public disclosure of the fact that a security vulnerability is being exploited in the wild. The session defined the difference between vulnerability disclosure and disclosure of exploitation, and illustrated scenarios in which exploitation information can help aid the public in defending against active threats, as well as scenarios in which exploitation information can result in increased attack activity.

Cross and Stewart discussed the ethics and timing of exploitation disclosure, presenting examples from various, real-world case studies. “Disclosing the fact that exploitation is occurring is important for many reasons, including helping IT professionals and software vendors prioritise defensive efforts,” said Stewart. “However, exploitation disclosure can also attract the attention of attackers and accelerate attack activity.”

“New vulnerabilities may be uncovered by security professionals in the course of analysing malware samples or investigating breaches,” said Cross. “These security professionals are faced with a challenging ethical dilemma. There is attack activity going on that needs to be stopped as soon as possible, but the responsible software vendor may not know about the vulnerability in question and may need time to prepare a patch. As these circumstances have become increasingly common, it is important to understand the associated ethical considerations.”

www.lancope.com

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Christina Alexander Judge - SecurityBuyer

Christina Alexander Announced as Security Buyer Awards Judge

Security Buyer is proud to announce Christina Alexander as the latest addition to the distinguished judging panel for the Security…
Milestone - SecurityBuyer

Milestone Systems updates across XProtect, BriefCam, Arcules

Milestone Systems today announced updates across its complete security technology portfolio with releases for XProtect
ASSA ABLOY SMARTair - Security Buyer

More flexible management of Gen-Z student accommodation

Almost everyone attending university for the first time is now a digital native. They expect the convenience…
ICT - securitybuyer

ICT announces Martin Vermaak as COO

Integrated Control Technology (ICT), a leading provider of intelligent access control, intrusion detection, building automation..
FLIR - security buyer

New FLIR camera for Perimeter Security

FLIR, a Teledyne Technologies company, today released its newest high-resolution visible/thermal security camera for commercial..
Contacta - Security Buyer

Contacta launches Level 8 ballistically-resistant window intercom

Assistive listening specialist, Contacta, has launched the world’s first window intercom system with a Level 8 UL752 approval.
Big Interview Abdullah Tanoli

Big Interview – Hero of Leicester Square

Rebecca Spayne of Security Buyer has the privilege of speaking with a real-life hero, Abdullah Tanoli, the hero of Leicester Square..
SentinelOne & AWS - Security Buyer

SentinelOne Teams with AWS to bring Cloud Security Protection

SentinelOne announced that it is a launch partner for the new AWS Security Hub. The new collaboration builds on a long standing..
Genetec - Security Buyer

Genetec and Hanwha Vision

The latest in our ongoing series introducing Hanwha Vision’s pioneering partners, leads us to Ben Durrant, Account Executive at Genetec Inc.
Altronix - SecurityBuyer

Altronix POE367 Delivers 277VAC Support

Altronix has expanded its power product line with the new POE367 power supply/charger designed specifically for 277VAC input environments.
Scroll to Top