Bugtraq relaunches at securityfocus.com under new ownership
A post to the bugtraq@securityfocus.com mailing list announces that its author has acquired securityfocus.com and the Bugtraq name and is relaunching the list. Bugtraq was created in 1993 by Scott Chasin as a place for full disclosure, where security researchers could publish vulnerabilities openly, without gatekeepers or politics; for over a decade it was described as the first place anything that mattered in security research would appear. The domain later changed hands through a chain of acquisitions, the archives went dark, and the list went silent, leaving a generation of researchers who grew up without it. The new owner says the relaunch is not meant to build a museum but to restart the conversation, keeping the mission unchanged: full disclosure, researcher-first, no corporate filter. The list address and purpose stay the same. The old archives, sourced from community copies of what was always public mailing list traffic, will be preserved and made accessible separately, though no timescale is given. The post frames the relaunch partly as a response to an erosion of cybersecurity history, with exploits, techniques and analyses scattered across dead links and defunct forums, and argues that in an era when AI can produce both knowledge and disinformation at high volume, preserving what was actually true and who actually did the work matters more than before. Researchers are invited to disclose vulnerabilities and share opinions on how disclosure should work in 2026 directly on the list. No date or price is given for the acquisition, and the post does not explain who previously owned securityfocus.com or why the archives went dark. The thread's only listed participant is Jonathan Brossard, though the post itself is unsigned in the body text.
Key facts
- Bugtraq, the full-disclosure vulnerability mailing list created by Scott Chasin in 1993, has been relaunched at its original address, bugtraq@securityfocus.com.
- The new owner says they acquired securityfocus.com and the Bugtraq name, though no date or price for the acquisition is disclosed.
- The list went dark after securityfocus.com changed hands through a chain of acquisitions; the relaunch keeps the same address and the stated mission: full disclosure, researcher-first, no corporate filter.
- The old Bugtraq archives, drawn from community copies of the historically public mailing list traffic, will be preserved and made accessible separately, with no timescale given.
- The relaunch post frames preserving vulnerability-research history as increasingly important given how fast AI can now produce both knowledge and disinformation.
Why it matters
Bugtraq was, for over a decade starting in 1993, the place where new vulnerability disclosures surfaced first, without a vendor or corporate filter shaping what got published. Its archives going dark left a gap in the historical record of security research, and the relaunch is explicitly framed as an attempt to restart that unfiltered disclosure channel rather than simply resurrect a brand.
Who it affects
Security researchers who want a venue to publish vulnerability findings without gatekeepers, and anyone who relied on the old Bugtraq archives as a reference for past exploits, techniques and analyses that have since scattered across dead links and defunct forums.
How to use it
The relaunched list runs at the same address, bugtraq@securityfocus.com. Researchers who find vulnerabilities are invited to disclose them there, and anyone with views on how disclosure should work in 2026 is invited to share them on the list as well.
How solid is it
The claim rests on a first-person post to the mailing list itself, stating that the author acquired securityfocus.com and the Bugtraq name; the post does not give a date or price for the acquisition, nor explain who owned the domain previously or why the archives went dark. The thread's sole listed participant is Jonathan Brossard, though the post body does not sign itself with that name.
Risks and caveats
No terms of the acquisition are disclosed, so it is not independently verifiable from the post alone who controls the list going forward or under what conditions. No timescale is given for when the preserved old archives will actually become accessible, and the post does not address why the domain went dark in the first place.
“The mission is unchanged: full disclosure, researcher-first, no corporate filter.”
— the relaunch post