Bugtraq Mailing List Relaunches Under New Owner
08 Aug 2026
Bugtraq, one of the earliest and most influential mailing lists for security vulnerability disclosure, has been relaunched — but under ownership that hasn't been publicly disclosed.
What happened
Scott Chasin created Bugtraq in 1993, and it went on to become a foundational venue for full-disclosure vulnerability reporting in the security community. According to the report, the securityfocus.com domain and the Bugtraq name have recently been acquired, and the list has been restarted at bugtraq@securityfocus.com.
The relaunched list's stated mission is blunt: full disclosure, researcher-first, no corporate filter. Security researchers remain the primary intended audience. Old Bugtraq archives — sourced from community copies of historical mailing list traffic — are also being preserved and made accessible separately, giving the security research community a way to reference decades of past disclosures.
No exact relaunch date is given in available information, and the new operators have not disclosed who acquired the domain and name, or whether they have any connection to the original Bugtraq/SecurityFocus team.
Timeline
- 1993: Scott Chasin creates Bugtraq.
- Recently (undated): The securityfocus.com domain and Bugtraq name are acquired.
- Recently (undated): Bugtraq relaunches as a mailing list at bugtraq@securityfocus.com.
What's unclear
Several important details are missing from what's currently known:
- Who or what entity now owns securityfocus.com and the Bugtraq brand.
- The precise relaunch date.
- How the list will be moderated or funded going forward, compared to its original run.
- Subscriber counts or activity levels since the restart.
- Whether the new operators have any relationship to the people who ran the original Bugtraq/SecurityFocus.
The risks
The lack of disclosed ownership raises legitimate questions about the list's independence and trustworthiness — a notable concern for any security-focused resource that researchers and vendors might rely on. Additionally, Bugtraq's full-disclosure policy, by design, can result in unpatched vulnerabilities being publicized before fixes are ready, a longstanding tension in the security disclosure debate.
Why founders should care
For founders building security products, this relaunch is likely worth watching but not yet worth building on top of. A revived, researcher-first disclosure channel could plausibly become a useful early-warning source for vulnerability and threat intelligence — the kind of signal that security startups have historically mined for competitive advantage. The restored archives may also prove valuable as a historical dataset for security research and tooling.
That said, the unresolved ownership question means founders should treat the list cautiously for now. Before integrating Bugtraq data into compliance workflows, threat intelligence pipelines, or customer-facing security claims, it would be prudent to verify who is actually running the list and how disclosures are vetted. Startups that move early to monitor the list — while remaining skeptical of its provenance — may be best positioned to benefit if it proves credible, without overexposing themselves if it doesn't.
Bottom line
Bugtraq's return is a notable moment for the security community, reviving a channel that shaped decades of vulnerability disclosure norms. But with ownership undisclosed and operational details thin, founders should watch closely rather than rely on it outright — at least until more clarity emerges about who's behind the relaunch.