← Microsec Ltd. cases
Bugzilla #1865880
Self Reported Incident
Microsec: Findings in 2023 Audit
RESOLVED
FIXED
Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Microsec Ltd. reported findings from a 2023 audit regarding the management of vulnerabilities in their JIRA system. The audit revealed that one vulnerability was not categorized correctly, impacting accountability for fix times. In response, Microsec implemented new rules for marking vulnerabilities, developed a JIRA filter for better tracking, and opened an Audit Incident Report with Mozilla detailing the issue and corrective actions. As of February 2024, all planned tasks have been completed, and Microsec is awaiting closure of the case.
Chronology
- Microsec opened an Audit Incident Report to address findings from the audit.
- Mozilla indicated plans to close the case unless further issues arise.
Thread Activity
- Microsec representative — Microsec reported findings from the audit and outlined action items to address vulnerabilities.
- Mozilla representative — Mozilla stated intentions to close the matter unless additional issues are raised.
- Microsec representative — Microsec clarified the nature of the audit finding and the actions taken to improve vulnerability management.
Participants
Microsec representative
Mozilla representative
External References
Similar Local Cases
Microsec: Expired Certificates on test Pages for Revocation
Microsec: CT Logging mistakes
Microsec: "DV valid" test website certificate issued under incorrect root
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields
Microsec: Inconsistent Disclosure of S/MIME BR Audit Information in CCADB
GlobalSign: Invalid countryName
Sectigo: Failure to provide a preliminary report within 24 hours
IdenTrust: Undisclosed Unrevoked ICAs