Navigating a Security Disaster
From Freakout to Fix
Ægis Initiative
Meet tabulex
A Phoenix table component driven entirely by URL parameters
Completely fictional, any similarities to existing libraries are incidental!
Ægis Initiative
You built something wonderful.
😍
⭐
⭐
Ægis Initiative
OOPS
What now?
Ægis Initiative
Jonatan Männchen�CISO @ Erlang Ecosystem Foundation
Ægis Initiative
What is going on? How bad is it? Who knows?
Ægis Initiative
Is it a vulnerability?
Ægis Initiative
Is it public?
Ægis Initiative
Confirmed RCE in tabulex
Ægis Initiative
2. Shed Shame
Mistakes happen. Hiding them makes things worse.
Ægis Initiative
63%�https://arxiv.org/pdf/2503.22134
Everyone Ships Bugs
Ægis Initiative
Shame → Trust
Owning up builds confidence; hiding erodes it.
Ægis Initiative
3. Coordinate Disclosure
Ægis Initiative
What is a CVE?
Ægis Initiative
EEF CNA Can Guide You
Ægis Initiative
CVE Assignment
Ægis Initiative
How to read a CVE?
Ægis Initiative
Common Vulnerability Scoring System�(CVSS)
Ægis Initiative
Narrative: PoC leaks
Should you disclose now?
| Patch Ready | Patch Not Ready |
Vulnerability Public | Publish Advisory & Patch | Disclose Immediately & Offer Mitigations |
Vulnerability Not Public | Plan Disclosure & Merge | Prepare in Private |
Ægis Initiative
4. Patch & Release
Ægis Initiative
Writing the Fix
Ægis Initiative
Release Fix & Publish Vulnerability
Ægis Initiative
Hex Version Retirement
Ægis Initiative
5. Communicate
Ægis Initiative
Inform Your Users
Ægis Initiative
Spread of Vulnerability Info
Ægis Initiative
6. Prepare for the next Time
Ægis Initiative
SECURITY.md
Ægis Initiative
Dependency Scanning / Updates
Ægis Initiative
Tips for Corporations
Ægis Initiative
Key Takeaways
Ægis Initiative
Q&A
Thanks to the sponsors of the EEF Ægis Initiative
Ægis Initiative