Coordinated disclosure

Acknowledgements

Researchers who found an issue and chose to tell us rather than sell it. Ordered by the date the report reached us.

Last updated 10 September 2026

This page records the people who submitted a valid finding under our Vulnerability Disclosure Policy. If you would rather not be named, say so and we will leave you off; a handle works too.

2026

No reports have been published under this policy yet. It took effect on 10 September 2026 — the first entry could be yours.

How an entry is earned

  • The report reached security@ongsec.com.
  • The finding falls inside the scope in section 1 of the policy and outside the exclusions in section 2.
  • The first person to report an issue is credited. Later reports count as duplicates, though a report demonstrating a new exploitation path is credited separately.
  • Entries are added once the fix has shipped.

What an entry contains

The researcher's name or handle, an optional link (personal site, social account), a short classification of the finding and the remediation date. Technical detail is not published here, so that similar systems elsewhere are not put at risk; the researcher is free to publish their own write-up.

Report an issue

Read the policy first, then write. First response: 2 business days.

security@ongsec.com
WhatsApp