LinkedIn·Wednesday, 29 July 2026·28d ago
Every vulnerability you've ever patched had a name before you met it. Someone gave it that name. This week, that someone was one of ours.…
Curios
996 followers
Every vulnerability you've ever patched had a name before you met it. Someone gave it that name.
This week, that someone was one of ours. Mateusz Gierblinski — Senior Information Security Engineer at Curios, 12 CVEs, OSCP — received a bug bounty from Microsoft's Security Response Center.
Most people meet CVEs as lines in a patch report. Few think about where they come from:
→ A researcher finds a flaw and reports it — before criminals find it
→ The flaw gets a name, a severity, a fix — one shared language for every scanner, SOC and patch cycle on earth
→ Everyone running that software is protected, whether they know it or not
Without the CVE program, every organisation discovers every flaw alone. Usually during the incident.
That's why we contribute. Mateusz Gierblinski latest disclosure got a widely-used open-source library patched for everyone. And the same research mindset powers what we do for clients: penetration testing with real exploitation paths, red teaming that tests whether anyone notices, vulnerability management from finding to fixing, and vCISO guidance that turns it into board decisions.
One researcher reports. Everyone is protected.
Congratulations, Mateusz Gierblinski. 👏
#CVE #ResponsibleDisclosure #OffensiveSecurity #PenTest #BugBounty #CyberSecurity
↻ 2
View on LinkedIn Cross-referenced
Related on the wire
Before you sign the next penetration test, check who the scope was written for. If it was written to satisfy an audit, it will pass an…
One of this week's 394 Microsoft fixes mentions us. CVE-2026-70324, elevation of privilege in SharePoint. The acknowledgement reads…
"Are we secure?" Someone asks it near the end. Item seven, after the budget, ten minutes left. We used to answer it. A slide, three green…
GDPR. NIS2. DORA. CRA. The AI Act. Five years ago your security program answered to one regulator. Soon it answers to five. The frameworks…
The CCB inspection notice lands on a Tuesday morning. No drama. Just a date. You registered long ago. But registration was never the finish…