{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T14:20:23Z","timestamp":1773670823708,"version":"3.50.1"},"reference-count":50,"publisher":"Association for Computing Machinery (ACM)","issue":"1","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,3,31]]},"abstract":"<jats:p>Vulnerability disclosure is the practice of a finder disclosing a newly found vulnerability to vendors. It has received best practices to ensure communication between stakeholders. However, the practice of a finder or vendor notifying end-users about vulnerable systems and mitigation plans has not received the same attention and guidelines for performing it at scale. We identify the practice as vulnerability notification, which shares similarities with disclosure but presents other challenges and requires different approaches.<\/jats:p>\n                  <jats:p>In vulnerability notification, a finder targets known vulnerabilities or misconfigurations using active scans or datasets to determine how many systems or services remain vulnerable. The scale and complexity of vulnerability notification to end-users are often significantly greater than those of multi-party disclosure to vendors. These place an increasing burden on finders to inform stakeholders on time, especially for academic security researchers, ethical hackers and practitioners.<\/jats:p>\n                  <jats:p>Based on our experience with notifications and academic publications documenting disclosure and notification operations, we conduct a meta-review of how researchers have adopted best practices, pursued different strategies and reflected on their operations over the years. Drawing on the meta-review and suggestions from security communities, we propose new best practices for finders to perform vulnerability disclosure, particularly vulnerability notification at scale.<\/jats:p>","DOI":"10.1145\/3777485","type":"journal-article","created":{"date-parts":[[2025,11,20]],"date-time":"2025-11-20T13:05:06Z","timestamp":1763643906000},"page":"1-20","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Vulnerability Disclosure or Notification? Best Practices for Reaching Stakeholders at Scale"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8759-6676","authenticated-orcid":false,"given":"Ting-Han","family":"Chen","sequence":"first","affiliation":[{"name":"University of Twente, Enschede, The Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5685-8714","authenticated-orcid":false,"given":"Jeroen","family":"van der Ham-de Vos","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, The Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,3,16]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Wikipedia. Badlock. 2024. Retrieved from https:\/\/en.wikipedia.org\/w\/index.php?title=Badlock&oldid=1206658510"},{"key":"e_1_3_2_3_2","first-page":"7135","volume-title":"Proceedings of the 34th USENIX Security Symposium (USENIX Security \u201925)","author":"Beitis Angelos","year":"2025","unstructured":"Angelos Beitis and Mathy Vanhoef. 2025. Haunted by legacy: Discovering and exploiting vulnerable tunnelling hosts. In Proceedings of the 34th USENIX Security Symposium (USENIX Security \u201925), 7135\u20137152. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity25\/presentation\/beitis"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3560835.3564555"},{"key":"e_1_3_2_5_2","unstructured":"Nicholas Boucher and Ross Anderson. 2023. Trojan Source Attacks. Retrieved from https:\/\/trojansource.codes\/"},{"key":"e_1_3_2_6_2","unstructured":"CERT\/CC. 2023. Vulnerability Information and Coordination Environment (VINCE). Retrieved from https:\/\/www.kb.cert.org\/vince"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW61312.2024.00039"},{"key":"e_1_3_2_8_2","unstructured":"Lucian Constantin. 2016. Hyped-Up Microsoft Samba \u201cBadlock\u201d Flaw Isn\u2019t Critical but Serious Enough. Retrieved from https:\/\/www.pcworld.com\/article\/420541\/microsoft-samba-badlock-flaw-not-critical-but-serious-enough.html"},{"key":"e_1_3_2_9_2","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA). 2020. BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy. Retrieved from https:\/\/www.cisa.gov\/news-events\/directives\/bod-20-01-develop-and-publish-vulnerability-disclosure-policy"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"e_1_3_2_11_2","unstructured":"Dutch Institute for Vulnerability Disclosure (DIVD). 2025. Retrieved from https:\/\/www.divd.nl\/"},{"key":"e_1_3_2_12_2","unstructured":"European Commission. 2022. Cyber Resilience Act (CRA). Retrieved from https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-56249-5_9"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1787\/abea0b69-en"},{"key":"e_1_3_2_15_2","unstructured":"Forum of Incident Response and Security Teams (FIRST). 2019. CSIRT Services Framework. Retrieved from https:\/\/www.first.org\/standards\/frameworks\/csirts\/csirt_services_framework"},{"key":"e_1_3_2_16_2","unstructured":"Forum of Incident Response and Security Teams (FIRST). 2020. Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure. Retrieved from https:\/\/www.first.org\/global\/sigs\/vulnerability-coordination\/multiparty\/guidelines-v1.1"},{"key":"e_1_3_2_17_2","unstructured":"Forum of Incident Response and Security Teams (FIRST). 2020. PSIRT Services Framework. Retrieved from https:\/\/www.first.org\/standards\/frameworks\/psirts\/psirt_services_framework"},{"key":"e_1_3_2_18_2","unstructured":"Forum of Incident Response and Security Teams (FIRST). 2020. Vulnerability Coordination SIG. Retrieved from https:\/\/www.first.org\/global\/sigs\/vulnerability-coordination\/"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","unstructured":"Edwin Foudil and Yakov Shafranovich. 2022. A File Format to Aid in Security Vulnerability Disclosure. Technical Report 9116. RFC Editor. DOI: 10.17487\/RFC9116","DOI":"10.17487\/RFC9116"},{"key":"e_1_3_2_20_2","unstructured":"Google. 2019. Project Zero: Vulnerability Disclosure FAQ. Retrieved from https:\/\/googleprojectzero.blogspot.com\/p\/vulnerability-disclosure-faq.html"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3477431"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","unstructured":"Allen D. Householder Garret Wassermann Art Manion and Chris King. 2017. The CERT Guide to Coordinated Vulnerability Disclosure. DOI: 10.1184\/R1\/12367340.v1","DOI":"10.1184\/R1\/12367340.v1"},{"key":"e_1_3_2_23_2","unstructured":"Information-technology Promotion Agency Japan (IPA). 2024. Information Security Early Warning Partnership | Enhancing Information Security. Retrieved from https:\/\/www.ipa.go.jp\/en\/security\/vulnerabilities\/partnership.html"},{"key":"e_1_3_2_24_2","unstructured":"INTERSECT. 2020. Towards an Internet of Secure Things. Retrieved from https:\/\/intersct.nl\/"},{"key":"e_1_3_2_25_2","unstructured":"Rob Knake. 2025. Improving Private Sector Cyber Victim Notification and Support. Retrieved from https:\/\/securityandtechnology.org\/virtual-library\/report\/improving-private-sector-cyber-victim-notification-and-support\/"},{"key":"e_1_3_2_26_2","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security)","author":"Li Frank","year":"2016","unstructured":"Frank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami, Michael Bailey, Damon McCoy, Stefan Savage, and Vern Paxson. 2016. You\u2019ve got vulnerability: Exploring effective vulnerability notifications. In Proceedings of the 25th USENIX Security Symposium (USENIX Security). USENIX Association. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/li"},{"key":"e_1_3_2_27_2","first-page":"2489","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security \u2019 21)","author":"Maass Max","unstructured":"Max Maass, Alina St\u00f6ver, Henning Prid\u00f6hl, Sebastian Bretthauer, Dominik Herrmann, Matthias Hollick, and Indra Spiecker. 2021. Effective notification campaigns on the web: A matter of trust, framing, and support. In Proceedings of the 30th USENIX Security Symposium (USENIX Security \u2019 21), 2489\u20132506. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/maass"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.techsoc.2020.101382"},{"key":"e_1_3_2_29_2","unstructured":"Microsoft. 2023. Exchange Online Limits - Service Descriptions. Retrieved from https:\/\/learn.microsoft.com\/en-us\/office365\/servicedescriptions\/exchange-online-service-description\/exchange-online-limits"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3610381.3610383"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329849"},{"key":"e_1_3_2_32_2","unstructured":"National Cyber Security Centre of The Netherlands (NCSC-NL). 2018. Coordinated Vulnerability Disclosure: The Guideline. Retrieved from https:\/\/english.ncsc.nl\/publications\/publications\/2019\/juni\/01\/coordinated-vulnerability-disclosure-the-guideline"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.14722\/ethics.2023.237352"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyab015"},{"key":"e_1_3_2_35_2","unstructured":"The Shadowserver Foundation. 2025. Lighting the way to a more secure Internet. Retrieved from https:\/\/www.shadowserver.org\/"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP60621.2024.00017"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23171"},{"key":"e_1_3_2_38_2","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security)","author":"Stock Ben","year":"2016","unstructured":"Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, and Michael Backes. 2016. Hey, you have a problem: On the feasibility of large-scale web vulnerability notification. In Proceedings of the 25th USENIX Security Symposium (USENIX Security). USENIX Association. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/stock"},{"key":"e_1_3_2_39_2","unstructured":"The Shadowserver Foundation. 2025. Open IP-Tunnel Report. Retrieved from https:\/\/www.shadowserver.org\/what-we-do\/network-reporting\/open-ip-tunnel-report\/"},{"key":"e_1_3_2_40_2","unstructured":"Jeroen van der Ham Andrea Continella Petri de Willigen and Dennis Reidsma. 2023. University of Twente Policy for Coordinated Vulnerability Disclosure in Research. Retrieved from https:\/\/www.utwente.nl\/en\/service-portal\/research-support\/procedures-facilities\/coordinated-vulnerability-disclosure-policy-for-research"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.13052\/jcsm2245-1439.543"},{"key":"e_1_3_2_42_2","unstructured":"Max van der Horst. 2023. Global Vulnerability Vigilance: Timely Disaster Notification using Internet-Scale Coordinated Vulnerability Disclosure. Retrieved from https:\/\/scripties.uba.uva.nl\/search?id=record_54279"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3617182"},{"key":"e_1_3_2_44_2","unstructured":"Mathy Vanhoef. 2017. KRACK Attacks: Breaking WPA2. Retrieved from https:\/\/www.krackattacks.com\/"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134027"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243807"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/IBF50092.2020.9034828"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102936"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1201\/9780203983836"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00032"},{"key":"e_1_3_2_51_2","volume-title":"Proceedings of the 16th Workshop on the Economics of Information Security (WEIS)","author":"\u00c7etin Or\u00e7un","year":"2017","unstructured":"Or\u00e7un \u00c7etin, Carlos Ga\u00f1\u00e1n, Maciej Korczy\u0144ski, and Michel van Eeten. 2017. Make notifications great again: Learning how to notify in the age of large-scale vulnerability scanning. In Proceedings of the 16th Workshop on the Economics of Information Security (WEIS). Retrieved from https:\/\/infosecon.net\/workshop\/downloads\/2017\/pdf\/Make_Notifications_Great_Again:_Learning_How_to_Notify_in_the_Age_of_Large-Scale_Vulnerability_Scanning.pdf"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3777485","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T13:07:18Z","timestamp":1773666438000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3777485"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,16]]},"references-count":50,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3,31]]}},"alternative-id":["10.1145\/3777485"],"URL":"https:\/\/doi.org\/10.1145\/3777485","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,16]]},"assertion":[{"value":"2025-05-20","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-27","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}