<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[The CopyFail announcement and handling is one of the least defender-supporting I think I&#x27;ve ever seen.]]></title><description><![CDATA[<p>The CopyFail announcement and handling is one of the least defender-supporting I think I've ever seen. </p><p>Mitigations were extremely thin at launch, and haven't improved much, and are even brittle and misleading:</p><p><a href="https://infosec.exchange/@tychotithonus/116490466168316767"><span>https://</span><span>infosec.exchange/@tychotithonu</span><span>s/116490466168316767</span></a></p><p>They've also largely neglected most of the value of the feedback they're getting from defenders clamoring for useful intel. The GitHub repo is full of feedback about which distros are affected or unaffected ... and a day later, none of it has been used to update the list of affected versions in the main README (except for the RHEL made-up version fix)</p><p>And this exchange is painful: </p><p><a href="https://github.com/theori-io/copy-fail-CVE-2026-31431/issues/12" rel="nofollow noopener"><span>https://</span><span>github.com/theori-io/copy-fail</span><span>-CVE-2026-31431/issues/12</span></a></p><p>"None of us are RH people so it wasn't caught" <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f610.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--neutral_face" style="height:23px;width:auto;vertical-align:middle" title="😐" alt="😐" /> You had <em>weeks</em> do basic vetting, or find someone who would help you.</p><p>Theori seems to have to have intended this to be a showcase for their product. Instead, it has convinced me that I will <em>never</em> buy anything from them.</p><p>Edit: Will Dorman goes into more detail here, 100% agreed: <br /><a href="https://infosec.exchange/@wdormann/116493725294723695"><span>https://</span><span>infosec.exchange/@wdormann/116</span><span>493725294723695</span></a></p><p><a href="https://infosec.exchange/tags/CopyFail" rel="tag">#<span>CopyFail</span></a> <a href="https://infosec.exchange/tags/cve_2026_31431" rel="tag">#<span>cve_2026_31431</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/2a08a5b5-5927-4541-88c8-984479011e07/the-copyfail-announcement-and-handling-is-one-of-the-least-defender-supporting-i-think-i-ve-ever-seen.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 06:46:11 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/2a08a5b5-5927-4541-88c8-984479011e07.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Apr 2026 13:38:24 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to The CopyFail announcement and handling is one of the least defender-supporting I think I&#x27;ve ever seen. on Thu, 30 Apr 2026 14:59:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/badsamurai%40infosec.exchange">@<span>badsamurai</span></a></span> <span><a href="/user/h2onolan%40infosec.exchange">@<span>h2onolan</span></a></span> <span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> he may have brought drone doctrine to infosec but can he repeat to make it a pseudo biz model <a href="https://infosec.exchange/tags/rev3" rel="tag">#<span>rev3</span></a> #.fail <a href="https://infosec.exchange/tags/greg" rel="tag">#<span>greg</span></a> <a href="https://infosec.exchange/tags/italy" rel="tag">#<span>italy</span></a> <a href="https://infosec.exchange/tags/one" rel="tag">#<span>one</span></a> trick pony</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/gary_alderson/statuses/116494250800167710</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/gary_alderson/statuses/116494250800167710</guid><dc:creator><![CDATA[gary_alderson@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 14:59:59 GMT</pubDate></item><item><title><![CDATA[Reply to The CopyFail announcement and handling is one of the least defender-supporting I think I&#x27;ve ever seen. on Thu, 30 Apr 2026 14:54:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/h2onolan%40infosec.exchange">@<span>h2onolan</span></a></span> <span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> </p><ol><li>Find vuln</li><li>Buy .fail domain</li><li>Bask in admiration and VC $</li></ol><p>Theori you need to figure out if you’re selling skateboards or doing real infosec.</p><p><a href="https://infosec.exchange/tags/copyfail" rel="tag">#<span>copyfail</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116494228203434744</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/badsamurai/statuses/116494228203434744</guid><dc:creator><![CDATA[badsamurai@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 14:54:15 GMT</pubDate></item><item><title><![CDATA[Reply to The CopyFail announcement and handling is one of the least defender-supporting I think I&#x27;ve ever seen. on Thu, 30 Apr 2026 14:20:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> agree, I mean this thing is everywhere. For example i think checkpoint firewalls are even RHEL…</p><p>Alot of scenarios of exploatation is unlikely but I think we will see attack chains coming weeks where this plays a crucial role in successful compromise.</p>]]></description><link>https://board.circlewithadot.net/post/https://swecyb.com/users/meriksson/statuses/116494096573763476</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://swecyb.com/users/meriksson/statuses/116494096573763476</guid><dc:creator><![CDATA[meriksson@swecyb.com]]></dc:creator><pubDate>Thu, 30 Apr 2026 14:20:46 GMT</pubDate></item><item><title><![CDATA[Reply to The CopyFail announcement and handling is one of the least defender-supporting I think I&#x27;ve ever seen. on Thu, 30 Apr 2026 14:20:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> Well said, all around. It seems like a loosey-goosey disclosure, with the highest emphasis on branding and generating hype.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/scottwilson/statuses/116494094434309014</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/scottwilson/statuses/116494094434309014</guid><dc:creator><![CDATA[scottwilson@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 14:20:14 GMT</pubDate></item><item><title><![CDATA[Reply to The CopyFail announcement and handling is one of the least defender-supporting I think I&#x27;ve ever seen. on Thu, 30 Apr 2026 13:52:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> there should be a playbook in the IR plan for “we found an exciting bug, now what?”</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/h2onolan/statuses/116493985415989455</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/h2onolan/statuses/116493985415989455</guid><dc:creator><![CDATA[h2onolan@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 13:52:30 GMT</pubDate></item><item><title><![CDATA[Reply to The CopyFail announcement and handling is one of the least defender-supporting I think I&#x27;ve ever seen. on Thu, 30 Apr 2026 13:48:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> If a random shitposter dropped this then I would understand not having the resources to research and follow up on it. But a startup trying to make a name for itself? It comes across as they got lucky, spent all their time and LLM tokens on hype, and then accidentally proved they don't actually know what they're doing.</p><p>I'm all for the disclosure of it, but the theatrics are more of the same overpromise / underdeliver that we've grown so tired of in this field.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116493970260630600</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116493970260630600</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 13:48:39 GMT</pubDate></item></channel></rss>