{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T14:58:27Z","timestamp":1775573907787,"version":"3.50.1"},"reference-count":78,"publisher":"Association for Computing Machinery (ACM)","issue":"2","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Cybersecurity is increasingly in the crosshairs of policymakers, as evidenced by the introduction of far-reaching legal frameworks around the globe. One concrete example of cybersecurity policy is how to deal with vulnerability disclosures. Organisations increasingly introduce vulnerability disclosure policies, and in some cases, public sector bodies are even required by law to have such policies. In this work, we study the effects of these policies in practice. Using the process specified on an organisation\u2019s web site, or absent such a process following community best practices, we disclose an e-mail vulnerability affecting a large number of organisations. This vulnerability allows arbitrary actors to send mail on behalf of affected organisations by abusing shared infrastructure. Our disclosure campaign focuses specifically on public and critical infrastructure organisations that are required by law to handle such disclosures. We find that having a policy makes it easier to contact organisations regarding security vulnerabilities. Nevertheless, even with a policy in place, over half of our reports remain unanswered and unresolved after 90 days. Based on our findings, we provide recommendations to policymakers and organisations how to better shape their vulnerability disclosure processes.<\/jats:p>","DOI":"10.1145\/3798280","type":"journal-article","created":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T14:05:55Z","timestamp":1771855555000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Your Disclosure Is Important to Us: An Analysis of Coordinated Vulnerability Disclosure Responses Using a Real Security Issue"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6574-2732","authenticated-orcid":false,"given":"Koen","family":"van Hove","sequence":"first","affiliation":[{"name":"NLnet Labs, Amsterdam, Netherlands and University of Twente, Enschede, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5685-8714","authenticated-orcid":false,"given":"Jeroen","family":"van der Ham-de Vos","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0249-8776","authenticated-orcid":false,"given":"Roland","family":"van Rijswijk-Deij","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,4,7]]},"reference":[{"key":"e_1_3_4_2_2","unstructured":"Postmaster Yahoo and AOL. 2023. More Secure Less Spam: Enforcing Email Standards for a Better Experience. Retrieved from https:\/\/blog.postmaster.yahooinc.com\/post\/730172167494483968\/more-secure-less-spam"},{"key":"e_1_3_4_3_2","unstructured":"ISO 27001: 2022. 2022. Information security cybersecurity and privacy protection\u2014Information security management systems\u2014Requirements. Standard International Organization for Standardization Geneva CH."},{"key":"e_1_3_4_4_2","unstructured":"ISO 27002:2022. 2022. Information security cybersecurity and privacy protection\u2014Information security controls. Standard International Organization for Standardization Geneva CH."},{"key":"e_1_3_4_5_2","unstructured":"ISO 29147:2018. 2018. Information technology\u2014Security techniques\u2014Vulnerability disclosure. Standard International Organization for Standardization Geneva CH."},{"key":"e_1_3_4_6_2","unstructured":"NTA 7516. 2019. Medische informatica\u2014Eisen voor veilige e-mail en chatapplicaties (uitwisseling van ad-hocberichten met persoonlijke gezondheidsinformatie). Standard Stichting Koninklijk Nederlands Normalisatie Instituut Delft NL."},{"key":"e_1_3_4_7_2","doi-asserted-by":"crossref","unstructured":"Eric P. Allman Jon Callas Jim Fenton Miles Libbey Michael Thomas and Mark Delany. 2007. DomainKeys Identified Mail (DKIM) Signatures. RFC 4871. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc4871","DOI":"10.17487\/rfc4871"},{"key":"e_1_3_4_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-006-9012-5"},{"key":"e_1_3_4_9_2","unstructured":"Jasper Bakker. 2023. Veel gemeenten gaan niet goed om met beveiligingsmeldingen blijkt uit onderzoek DIVD en Universiteit Twente. Retrieved from https:\/\/www.agconnect.nl\/tech-en-toekomst\/security\/veel-gemeenten-gaan-niet-goed-om-met-beveiligingsmeldingen"},{"key":"e_1_3_4_10_2","unstructured":"Belgisch Staatsblad. 2022. Wet betreffende de bescherming van melders van inbreuken op het Unie- of nationale recht vastgesteld binnen een juridische entiteit in de private sector. Retrieved from https:\/\/www.ejustice.just.fgov.be\/cgi\/article_body.pl?language=nl&caller=summary&pub_date=22-12-15&numac=2022042980"},{"key":"e_1_3_4_11_2","unstructured":"Belgisch Staatsblad. 2022. Wet betreffende de meldingskanalen en de bescherming van de melders van integriteitsschendingen in de federale overheidsinstanties en bij de ge\u00efntegreerde politie. Retrieved from https:\/\/www.ejustice.just.fgov.be\/cgi\/article_body.pl?language=nl&caller=summary&pub_date=22-12-23&numac=2022034749"},{"key":"e_1_3_4_12_2","unstructured":"Jeffrey Bencteux Martin Sohn Christensen and Sebastian Andersen. 2022. All your SPF includes are belong to US. Retrieved from https:\/\/improsec.com\/tech-blog\/arebelongtous"},{"key":"e_1_3_4_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/3517745.3561468"},{"key":"e_1_3_4_14_2","unstructured":"Binnenlands Bestuur. 2023. Gemeenten laks met meldingen hackers. Retrieved from https:\/\/www.binnenlandsbestuur.nl\/digitaal\/meldingen-van-kwetsbaarheden-worden-niet-altijd-opgepakt"},{"key":"e_1_3_4_15_2","unstructured":"BIO-Overheid. 2020. BIO v1.4zv. Retrieved from https:\/\/bio-overheid.nl\/media\/13kduqsi\/bio-versie-104zv_def.pdf"},{"key":"e_1_3_4_16_2","doi-asserted-by":"crossref","first-page":"298","DOI":"10.1007\/11766155_21","volume-title":"Emerging Trends in Information and Communication Security","author":"B\u00f6hme Rainer","year":"2006","unstructured":"Rainer B\u00f6hme. 2006. A comparison of market approaches to software vulnerability disclosure. In Emerging Trends in Information and Communication Security. G\u00fcnter M\u00fcller (Ed.), Springer Berlin, Berlin, 298\u2013311."},{"key":"e_1_3_4_17_2","doi-asserted-by":"publisher","DOI":"10.3390\/jcp1020015"},{"key":"e_1_3_4_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2007.26"},{"key":"e_1_3_4_19_2","unstructured":"CISA. 2023. Coordinated Vulnerability Disclosure Process. Retrieved from https:\/\/www.cisa.gov\/coordinated-vulnerability-disclosure-process"},{"key":"e_1_3_4_20_2","unstructured":"Council of European Union. 2016. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation). Retrieved from https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj"},{"key":"e_1_3_4_21_2","unstructured":"Council of European Union. 2019. Regulation (EU) 2019\/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526\/2013 (Cybersecurity Act). Retrieved from https:\/\/eur-lex.europa.eu\/eli\/reg\/2019\/881\/oj\/eng"},{"key":"e_1_3_4_22_2","unstructured":"Council of European Union. 2022. Directive (EU) 2022\/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union amending Regulation (EU) No 910\/2014 and Directive (EU) 2018\/1972 and repealing Directive (EU) 2016\/1148 (NIS 2 Directive). Retrieved from https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\/2022-12-27\/eng"},{"key":"e_1_3_4_23_2","unstructured":"Council of European Union. 2022. Proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019\/1020. Retrieved from https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex:52022PC0454"},{"key":"e_1_3_4_24_2","unstructured":"Council of European Union. 2024. Commission Implementing Regulation (EU) 2024\/482 of 31 January 2024 laying down rules for the application of Regulation (EU) 2019\/881 of the European Parliament and of the Council as regards the adoption of the European Common Criteria-based cybersecurity certification scheme (EUCC). Retrieved from https:\/\/eur-lex.europa.eu\/eli\/reg_impl\/2024\/482\/oj\/eng"},{"key":"e_1_3_4_25_2","doi-asserted-by":"crossref","unstructured":"Dave Crocker. 2009. RFC 4871 DomainKeys Identified Mail (DKIM) Signatures\u2014Update. RFC 5672. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc5672","DOI":"10.17487\/rfc5672"},{"key":"e_1_3_4_26_2","unstructured":"ENISA. 2021. Cybersecurity Certification: Candidate EUCC Scheme. Retrieved from https:\/\/www.enisa.europa.eu\/publications\/cybersecurity-certification-eucc-candidate-scheme"},{"key":"e_1_3_4_27_2","unstructured":"ENISA. 2023. Developing National Vulnerabilities Programmes. Retrieved from https:\/\/www.enisa.europa.eu\/publications\/developing-national-vulnerabilities-programmes"},{"key":"e_1_3_4_28_2","doi-asserted-by":"crossref","unstructured":"Jim Fenton. 2006. Analysis of Threats Motivating DomainKeys Identified Mail (DKIM). RFC 4686. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc4686","DOI":"10.17487\/rfc4686"},{"key":"e_1_3_4_29_2","unstructured":"FIRST. 2022. Traffic Light Protocol (TLP). Retrieved from https:\/\/www.first.org\/tlp\/"},{"key":"e_1_3_4_30_2","unstructured":"Forum Standaardisatie. DKIM. Retrieved from https:\/\/www.forumstandaardisatie.nl\/open-standaarden\/dkim"},{"key":"e_1_3_4_31_2","unstructured":"Forum Standaardisatie. DMARC. Retrieved from https:\/\/www.forumstandaardisatie.nl\/open-standaarden\/dmarc"},{"key":"e_1_3_4_32_2","unstructured":"Forum Standaardisatie. Leveranciersmanifest. Retrieved from https:\/\/forumstandaardisatie.nl\/leveranciersmanifest"},{"key":"e_1_3_4_33_2","unstructured":"Forum Standaardisatie. security.txt. Retrieved from https:\/\/www.forumstandaardisatie.nl\/open-standaarden\/securitytxt"},{"key":"e_1_3_4_34_2","unstructured":"Forum Standaardisatie. SPF. Retrieved from https:\/\/www.forumstandaardisatie.nl\/open-standaarden\/spf"},{"key":"e_1_3_4_35_2","unstructured":"Forum Standaardisatie. 2022. Bredere aanpak \u201cmeting informatieveiligheidstandaarden\u201d legt Achterblijvers Bloot. Retrieved from https:\/\/www.forumstandaardisatie.nl\/nieuws\/bredere-aanpak-meting-informatieveiligheidstandaarden-legt-achterblijvers-bloot"},{"key":"e_1_3_4_36_2","doi-asserted-by":"crossref","unstructured":"Edwin Foudil and Yakov Shafranovich. 2022. A File Format to Aid in Security Vulnerability Disclosure. RFC 9116. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc9116","DOI":"10.17487\/RFC9116"},{"key":"e_1_3_4_37_2","doi-asserted-by":"publisher","unstructured":"G. Draper Gil G. Kampourakis G. Karopoulos and Sanchez Martin Ji. 2022. Email Communication Security Standards: An Analysis of Uptake in the EU. (KJ-NA-31-280-EN-N (online)). DOI: 10.2760\/726094","DOI":"10.2760\/726094"},{"key":"e_1_3_4_38_2","doi-asserted-by":"crossref","unstructured":"Randall Gellens and Dr John C. Klensin. 1998. Message Submission. RFC 2476. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc2476","DOI":"10.17487\/rfc2476"},{"key":"e_1_3_4_39_2","unstructured":"Google. 2023. Email Sender Guidelines. Retrieved from https:\/\/support.google.com\/a\/answer\/81126"},{"key":"e_1_3_4_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCIT.2008.82"},{"key":"e_1_3_4_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2018.00020"},{"key":"e_1_3_4_42_2","unstructured":"IBD. 2023. IBD roept gemeenten op hun \u2018Coordinated Vulnerability Disclosure\u2019-proces onder de loep te nemen. Retrieved from https:\/\/www.informatiebeveiligingsdienst.nl\/nieuws\/ibd-roept-gemeenten-op-hun-coordinated-vulnerability-disclosure-proces-onder-de-loep-te-nemen\/"},{"key":"e_1_3_4_43_2","unstructured":"iBestuur. 2023. IBD roept gemeenten op eigen CVD-procedure te bekijken. Retrieved from https:\/\/ibestuur.nl\/artikel\/ibd-roept-gemeenten-op-eigen-cvd-procedure-te-bekijken\/"},{"key":"e_1_3_4_44_2","unstructured":"Naoya Kitagawa Toshiki Tanaka Masami Fukuyama and Nariyoshi Yam. 2016. Design and Implementation of a DMARC Verification Result Notification System. Retrieved from https:\/\/web.archive.org\/web\/20200620235543\/http:\/\/journals.sfu.ca\/apan\/index.php\/apan\/article\/download\/209\/pdf_121"},{"key":"e_1_3_4_45_2","doi-asserted-by":"crossref","unstructured":"Scott Kitterman. 2014. Sender Policy Framework (SPF) for Authorizing Use of Domains in Email Version 1. RFC 7208. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc7208","DOI":"10.17487\/rfc7208"},{"key":"e_1_3_4_46_2","doi-asserted-by":"crossref","unstructured":"Dr John C. Klensin. 2008. Simple Mail Transfer Protocol. RFC 5321. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc5321","DOI":"10.17487\/rfc5321"},{"issue":"1","key":"e_1_3_4_47_2","first-page":"35","article-title":"\u201cObjection, your honor!\u201d: false positive detection in sender domain authentication by utilizing the DMARC reports","volume":"13","author":"Konno Kanako","year":"2020","unstructured":"Kanako Konno, Naoya Kitagawa, and Nariyoshi Yamai. 2020. \u201cObjection, your honor!\u201d: false positive detection in sender domain authentication by utilizing the DMARC reports. International Journal on Advances in Internet Technology 13, 1&2 (Jun. 2020), 35\u201345.","journal-title":"International Journal on Advances in Internet Technology"},{"key":"e_1_3_4_48_2","doi-asserted-by":"crossref","unstructured":"Murray Kucherawy Dave Crocker and Tony Hansen. 2011. DomainKeys Identified Mail (DKIM) Signatures. RFC 6376. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc6376","DOI":"10.17487\/rfc6377"},{"key":"e_1_3_4_49_2","doi-asserted-by":"crossref","unstructured":"Murray Kucherawy and Elizabeth Zwicky. 2015. Domain-based Message Authentication Reporting and Conformance (DMARC). RFC 7489. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc7489","DOI":"10.17487\/rfc7489"},{"key":"e_1_3_4_50_2","first-page":"1033","volume-title":"25th USENIX Security Symposium (USENIX Security \u201916)","author":"Li Frank","year":"2016","unstructured":"Frank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami, Michael Bailey, Damon McCoy, Stefan Savage, and Vern Paxson. 2016. You\u2019ve got vulnerability: Exploring effective vulnerability notifications. In 25th USENIX Security Symposium (USENIX Security \u201916). USENIX Association, Austin, TX, 1033\u20131050. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/li"},{"key":"e_1_3_4_51_2","doi-asserted-by":"crossref","unstructured":"Enze Liu Gautam Akiwate Mattijs Jonker Ariana Mirian Grant Ho Geoffrey M. Voelker and Stefan Savage. 2023. Forward Pass: On the Security Implications of Email Forwarding Mechanism and Policy. Retrieved from https:\/\/arxiv.org\/abs\/2302.07287","DOI":"10.1109\/EuroSP57164.2023.00030"},{"key":"e_1_3_4_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3341495"},{"key":"e_1_3_4_53_2","unstructured":"Maggie Miller. 2024. The Nation\u2019s Best Hackers Found Vulnerabilities in Voting Machines\u2014But No Time to Fix Them. Retrieved from https:\/\/www.politico.com\/news\/2024\/08\/12\/hackers-vulnerabilities-voting-machines-elections-00173668"},{"key":"e_1_3_4_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3065422"},{"key":"e_1_3_4_55_2","doi-asserted-by":"crossref","unstructured":"John G. Myers. 1999. SMTP Service Extension for Authentication. RFC 2554. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc2554","DOI":"10.17487\/rfc2554"},{"key":"e_1_3_4_56_2","unstructured":"National Telecommunications and Information Administration. 2016. Vulnerability Disclosure Attitudes and Actions. Retrieved from https:\/\/www.ntia.doc.gov\/files\/ntia\/publications\/2016_ntia_a_a_vulnerability_disclosure_insights_report.pdf"},{"key":"e_1_3_4_57_2","unstructured":"NCSC-NL. 2018. Coordinated Vulnerability Disclosure: The Guideline. Retrieved from https:\/\/english.ncsc.nl\/publications\/publications\/2019\/juni\/01\/coordinated-vulnerability-disclosure-the-guideline"},{"key":"e_1_3_4_58_2","unstructured":"NCSC-UK. 2020. Vulnerability Disclosure Toolkit. Retrieved from https:\/\/www.ncsc.gov.uk\/information\/vulnerability-disclosure-toolkit"},{"key":"e_1_3_4_59_2","unstructured":"NOS. 2023. Hackers: \u2018Veel gemeenten reageren niet adequaat op veiligheidslekken\u2019. Retrieved from https:\/\/nos.nl\/artikel\/2492689-hackers-veel-gemeenten-reageren-niet-adequaat-op-veiligheidslekken"},{"key":"e_1_3_4_60_2","unstructured":"OECD. 2021. Encouraging Vulnerability Treatment. Retrieved from https:\/\/www.oecd-ilibrary.org\/content\/paper\/0e2615ba-en"},{"key":"e_1_3_4_61_2","unstructured":"Platform Internetstandaarden. 2017. Intentieverklaring Veilige E-mail Coalitie. Retrieved from https:\/\/nl.internet.nl\/static\/article\/nederland-voor-veilig-emailverkeer\/20170201a_Intentieverklaring_Veilige_E-mail_Coalitie.pdf"},{"key":"e_1_3_4_62_2","doi-asserted-by":"crossref","unstructured":"Jonathan B. Postel. 1981. Simple Mail Transfer Protocol. RFC 788. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc788","DOI":"10.17487\/rfc0788"},{"key":"e_1_3_4_63_2","doi-asserted-by":"crossref","unstructured":"Pete Resnick. 2008. Internet Message Format. RFC 5322. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc5322","DOI":"10.17487\/rfc5322"},{"key":"e_1_3_4_64_2","unstructured":"Rijksoverheid. 2023. Besluit op Woo-verzoek over domeinnaamregister Rijksoverheid. Retrieved from https:\/\/www.rijksoverheid.nl\/documenten\/woo-besluiten\/2023\/03\/20\/besluit-op-woo-verzoek-over-domeinnaamregister-rijksoverheid"},{"key":"e_1_3_4_65_2","unstructured":"Sebastian Salla. 2022. Scanning millions of domains and compromising email supply chains. Retrieved from https:\/\/caniphish.com\/phishing-resources\/blog\/compromising-australian-supply-chains-at-scale"},{"key":"e_1_3_4_66_2","article-title":"SpamChannel: Spoofing emails from 2 million+ domains and virtually becoming satan","volume":"31","author":"Salvati Marcello","year":"2023","unstructured":"Marcello Salvati. 2023. SpamChannel: Spoofing emails from 2 million+ domains and virtually becoming satan. Defcon 31 (2023). Retrieved from https:\/\/www.youtube.com\/watch?v=NwnT15q_PS8","journal-title":"Defcon"},{"key":"e_1_3_4_67_2","unstructured":"Wayne Schlitt and Meng Weng Wong. 2006. Sender Policy Framework (SPF) for Authorizing Use of Domains in E-Mail Version 1. RFC 4408. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc4408"},{"key":"e_1_3_4_68_2","first-page":"3201","volume-title":"30th USENIX Security Symposium (USENIX Security \u201921)","author":"Shen Kaiwen","year":"2021","unstructured":"Kaiwen Shen, Chuhan Wang, Minglei Guo, Xiaofeng Zheng, Chaoyi Lu, Baojun Liu, Yuxuan Zhao, Shuang Hao, Haixin Duan, Qingfeng Pan, et al. 2021. Weak links in authentication chains: A large-scale analysis of email sender spoofing attacks. In 30th USENIX Security Symposium (USENIX Security \u201921). USENIX Association, 3201\u20133217. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/shen-kaiwen"},{"key":"e_1_3_4_69_2","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1280"},{"key":"e_1_3_4_70_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23171"},{"key":"e_1_3_4_71_2","first-page":"1015","volume-title":"25th USENIX Security Symposium (USENIX Security \u201916)","author":"Stock Ben","year":"2016","unstructured":"Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, and Michael Backes. 2016. Hey, you have a problem: On the feasibility of large-scale web vulnerability notification. In 25th USENIX Security Symposium (USENIX Security \u201916). USENIX Association, Austin, TX, 1015\u20131032. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/stock"},{"key":"e_1_3_4_72_2","unstructured":"Nati Tal. 2024. \u201cEchospoofing\u201d\u2014A massive phishing campaign exploiting proofpoint\u2019s email protection to dispatch millions of perfectly spoofed emails. Retrieved from https:\/\/labs.guard.io\/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6"},{"key":"e_1_3_4_73_2","unstructured":"TransIP. 2023. Ik wil een contactformulier op mijn website gebruiken. Retrieved from https:\/\/www.transip.nl\/knowledgebase\/artikel\/230-wil-contactformulier-mijn-website-gebruiken\/"},{"key":"e_1_3_4_74_2","volume-title":"5th Workshop on Cyber Security Experimentation and Test (CSET \u201912)","author":"Vasek Marie","year":"2012","unstructured":"Marie Vasek and Tyler Moore. 2012. Do malware reports expedite cleanup? An experimental study. In 5th Workshop on Cyber Security Experimentation and Test (CSET \u201912). USENIX Association, Bellevue, WA, 6 pages. Retrieved from https:\/\/www.usenix.org\/conference\/cset12\/workshop-program\/presentation\/Vasek"},{"key":"e_1_3_4_75_2","doi-asserted-by":"crossref","first-page":"102936","DOI":"10.1016\/j.cose.2022.102936","article-title":"Coordinated vulnerability disclosure programme effectiveness: Issues and recommendations","volume":"123","author":"Walshe T.","year":"2022","unstructured":"T. Walshe and A. C. Simpson. 2022. Coordinated vulnerability disclosure programme effectiveness: Issues and recommendations. Computers and Security 123 (2022), 102936. Retrieved from https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404822003285","journal-title":"Computers and Security"},{"key":"e_1_3_4_76_2","volume-title":"Proceedings of the 31st Annual Network and Distributed System Security Symposium (NDSS \u201924)","author":"Wang Chuhan","year":"2024","unstructured":"Chuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang, Linkai Zheng, Lixiang, Jianjun Chen, Haixin Duan, Yanzhong Lin, and Qingfeng Pan. 2024. BreakSPF: How shared infrastructures magnify SPF vulnerabilities across the internet. In Proceedings of the 31st Annual Network and Distributed System Security Symposium (NDSS \u201924)."},{"key":"e_1_3_4_77_2","first-page":"1185","volume-title":"31st USENIX Security Symposium (USENIX Security \u201922)","author":"Wang Chuhan","year":"2022","unstructured":"Chuhan Wang, Kaiwen Shen, Minglei Guo, Yuxuan Zhao, Mingming Zhang, Jianjun Chen, Baojun Liu, Xiaofeng Zheng, Haixin Duan, Yanzhong Lin, et al. 2022. A large-scale and longitudinal measurement study of DKIM deployment. In 31st USENIX Security Symposium (USENIX Security \u201922). USENIX Association, Boston, MA, 1185\u20131201. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/wang-chuhan"},{"key":"e_1_3_4_78_2","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyw005"},{"issue":"3","key":"e_1_3_4_79_2","doi-asserted-by":"crossref","first-page":"508","DOI":"10.1016\/j.clsr.2017.11.003","article-title":"From responsible disclosure policy (RDP) towards state regulated responsible vulnerability disclosure procedure (hereinafter\u2014RVDP): The Latvian approach","volume":"34","author":"\u0136inis Uldis","year":"2018","unstructured":"Uldis \u0136inis. 2018. From responsible disclosure policy (RDP) towards state regulated responsible vulnerability disclosure procedure (hereinafter\u2014RVDP): The Latvian approach. Computer Law and Security Review 34, 3 (2018), 508\u2013522. Retrieved from https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0267364917303606","journal-title":"Computer Law and Security Review"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3798280","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T14:16:51Z","timestamp":1775571411000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3798280"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,7]]},"references-count":78,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3798280"],"URL":"https:\/\/doi.org\/10.1145\/3798280","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,7]]},"assertion":[{"value":"2025-03-27","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-02-17","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}