← Chunghwa Telecom cases
Bugzilla #2009046 Self Reported Incident Audit Finding

Chunghwa Telecom: Delayed disclosure to Bug 2008799 GTLSCA Audit Incident Report #3 - Missing vulnerability scan

RESOLVED FIXED Chunghwa Telecom
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Chunghwa Telecom (GTLSCA) reported a compliance/process “Delayed Disclosure” incident related to its annual WebTrust audit. The annual audit report was obtained on 2025/12/13, and the CA became aware of an audit finding (Bug 2008799) that was not disclosed in the public incident report by 2026/1/6. The finding concerned missing vulnerability scanning, where the auditor cited inadequate validation of the scanning methodology and scope performed by a third-party cybersecurity service provider, resulting in certain website hosts being excluded from vulnerability scans. The CA stated that, under CCADB Policy 5.2, audit “findings” must be disclosed to Bugzilla within 72 hours, and that this disclosure was not completed within the required timeframe. The CA said the issue was ultimately reported after a third party notified it of the deficiency, prompting corrective disclosure. The thread includes action items such as CCADB Policy 5.2 training (including the 72-hour disclosure rule), adding a CCADB disclosure decision gate to the audit workflow, and deploying an audit-finding monitoring dashboard, and it requests closure. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:37 UTC Revised: 2026-06-16 18:10 UTC Confidence: 0.50 8 comments
Chronology
  1. The CA states the non-compliance period began (required 72-hour disclosure window was missed).
  2. The CA obtained the annual audit report containing the audit finding.
  3. The CA states the audit finding was identified and not disclosed in the public incident report by this date.
  4. The CA posted the full incident report for the delayed disclosure case.
  5. The incident report was scheduled to be closed (final call for comments).
Thread Activity
  1. Cht representative — Posted a preliminary incident report stating the CA became aware of an audit finding not disclosed in the public incident report and that the source of disclosure was third-party reported.
  2. Cht representative — Posted a full incident report describing the missing vulnerability scan finding, the missed 72-hour disclosure requirement under CCADB Policy 5.2, and the timeline of non-compliance.
  3. Cht representative — Updated the full incident report to fix a typo.
  4. Cht representative — Stated Chunghwa Telecom was monitoring the bug and had no new information.
  5. Cht representative — Provided an action-items update including corrective disclosure completion, CCADB Policy 5.2 training, adding a disclosure decision gate, and deploying an audit-finding monitoring dashboard.
  6. Cht representative — Provided a follow-up action-items update with statuses for the listed remediation steps.
  7. Cht representative — Submitted a report closure summary describing root causes and remediation, stating action items were completed and requesting closure.
  8. CCADB representative — Issued a final call for comments and stated the incident report would be closed on approximately 2026-02-19.
Participants
Cht representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 100% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2009048 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 100% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008803 GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#2008799 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-19 · 92% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 88% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 87% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2009043 RESOLVED Delayed Revocation Opened 2026-01-07 · Closed 2026-02-19 · 81% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008782 GTLSCA Audit Incident Report #1 - mass certificate revocation plan
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 75% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#2025231 RESOLVED Delayed Revocation Opened 2026-03-23 · Closed 2026-04-24 · 69% similar
Chunghwa Telecom: Test Website certificate not revoked

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action