SecurityFocus
- Company typePrivate
- Founded1993
- HeadquartersMountain View, United States
- Headcount251–500
- GTM typeB2C
- OfferingDigital Commerce or Content
What SecurityFocus does
SecurityFocus is an online computer security news portal and information security services platform that operates a pair of curated, moderated mailing lists for the global security research community. Its flagship product, Bugtraq, was founded in 1993 by Scott Chasin and became the primary channel for vulnerability disclosure, security advisories, and original research for over two decades, setting the de facto standard for coordinated disclosure across proprietary, open source, hardware, firmware, and embedded targets. The platform's underlying technology is a mailing list infrastructure (Postorius for subscription management, HyperKitty for archives) hosted at lists.securityfocus.com, supplemented by external archival partnerships with MARC (1993-2021) and Openwall (2003-2021) that preserve the historical vulnerability disclosure corpus.
The company's business model is community-driven rather than commercially monetized. No pricing is publicly disclosed and the service operates as a community-supported initiative under independent stewardship after successive corporate owners (Symantec from 2002, Accenture from 2020) failed to sustain it, with Accenture initially attempting to shut down Bugtraq before reversing course under community pressure. The last message before the gap was posted on January 17, 2021. Bugtraq was relaunched in 2024 under community stewardship operated by PSIRT, alongside a new Bugtraq AI list dedicated to AI/ML vulnerability research covering model exploits, inference attacks, training data poisoning, framework vulnerabilities, and adversarial machine learning. Customer segments are individual security researchers and the broader security community, served globally via self-serve email subscription.
SecurityFocus firmographics
Firmographics- Name
- SecurityFocus
- Website
- https://securityfocus.com
- Company type
- Private
- Founded year
- 1993
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Ownership category
- akta.pro rank
SecurityFocus industry classification
Industry- Product category
- Vulnerability Disclosure Services
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
- akta.pro secondary industry
- Threat Intelligence Services (BPAEADAC)
Keywords
Where SecurityFocus is headquartered
LocationHeadquarters
- HQ city
- Mountain View
- HQ country
- United States
- HQ region
- North America
Markets served
SecurityFocus business model
Business model- GTM type
- B2C
- Offering type
- Digital Commerce or Content
- Cost components
- Technology or R&D, Personnel, Operations, Infrastructure
Revenue model
- Community Mailing List Services: Free community-driven mailing list services. Revenue model not publicly disclosed in available sources.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels2 records
SecurityFocus product offering
Product offeringCore offering
SecurityFocus operates a platform of two curated, moderated mailing lists for the security research community. The flagship Bugtraq list (founded 1993) provides vulnerability disclosure and security advisories across proprietary, open source, hardware, firmware, and embedded systems targets. Bugtraq AI is a newer list dedicated to vulnerability disclosures and security research focused on AI/ML systems, covering model exploits, inference attacks, training data poisoning, framework vulnerabilities, and adversarial machine learning. Both lists accept open submissions from security researchers worldwide and are accessible via public archives.
Product overview
SecurityFocus operates a platform of two curated, moderated mailing lists for the security research community. The flagship Bugtraq list (founded 1993) provides vulnerability disclosure and security advisories across all target types. Bugtraq AI is a newer list focused specifically on AI/ML system vulnerabilities including model exploits, inference attacks, training data poisoning, and adversarial machine learning. Both lists accept submissions from security researchers worldwide and are open to subscriptions.
Differentiator
Problem solved
Functional benefit
Brands
- Bugtraq: Curated vulnerability disclosure and security advisory mailing list covering all targets — proprietary, open source, hardware, firmware, embedded systems. The continuation of the original Bugtraq founded in 1993.
- Bugtraq AI
Products and services
- Bugtraq Curated vulnerability disclosure and security advisory mailing list covering all targets — proprietary, open source, hardware, firmware, and embedded systems. Moderated for quality. The continuation of the original Bugtraq founded in 1993, serving security researchers and the broader security community worldwide.
- Bugtraq AI Mailing list dedicated to vulnerability disclosures and security research focused on AI/ML systems, covering model exploits, inference attacks, training data poisoning, framework vulnerabilities, and adversarial machine learning. Targeted at security researchers investigating emerging AI/ML attack surfaces.
Companies that use SecurityFocus
Customer profileSegments2 records
Ideal customer profiles1 record
SecurityFocus technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature2 records
SecurityFocus partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered minor.
- MARC (Mailing List Archive Research Center)minorMARC preserves the historical Bugtraq archives from 1993–2021, providing external backup and access to the complete historical vulnerability disclosure database.
- OpenwallminorOpenwall preserves the Bugtraq archives from 2003–2021, providing external archival of vulnerability disclosures during the Symantec/Broadcom era.
Scale indicators1 record
Recent moves5 records
Expansion highlights3 records
SecurityFocus competitors and assessment
Company assessmentBroad incumbents
- Tenable: Major vulnerability management platform (Nessus) that integrates vulnerability intelligence and feeds into enterprise security workflows. Comparable as a vulnerability intelligence provider, though operating in the broader vulnerability management space rather than community disclosure.
- Qualys: Cloud-based vulnerability management and security platform providing vulnerability intelligence, scanning, and threat feeds. Comparable as a vulnerability intelligence and exposure management provider, though more focused on enterprise scanning than community disclosure.
- Rapid7: Cybersecurity analytics and vulnerability management platform offering vulnerability intelligence, disclosure, and management tools. Comparable as a vulnerability intelligence provider serving enterprises, with broader scope beyond community disclosure.
- NVD (National Vulnerability Database): U.S. government repository of vulnerability data based on CVE entries. Highly comparable as a centralized vulnerability intelligence source, with broader institutional backing but less community-driven curation than Bugtraq.
Direct peers
- Bugcrowd: Crowdsourced cybersecurity platform offering bug bounty and vulnerability disclosure programs. Direct competitor in the vulnerability disclosure and coordination space, serving a similar researcher community with a more structured, paid platform model.
- MITRE Corporation (CVE Program): Operates the CVE program, which is the foundational standard for vulnerability identification and disclosure that Bugtraq helped originate. Highly comparable as the institutional backbone of coordinated vulnerability disclosure, with a different operating model (standards body vs. mailing list).
- HackerOne: Leading bug bounty and vulnerability disclosure platform that connects security researchers with organizations for coordinated disclosure. Compares directly to Bugtraq as a community-driven channel for vulnerability reporting, with a more commercialized, monetized model.
- Seclists (Full Disclosure): Hosts the Full Disclosure mailing list, a direct historical alternative to Bugtraq for unmoderated vulnerability disclosure. Compares directly as a community-driven mailing list for vulnerability research and security advisories.
Emerging players
- Openwall Project: Community-driven open-source security project that hosts mailing lists including the Bugtraq archive. Highly comparable as a community-moderated security mailing list and vulnerability research forum, though smaller and more security-tooling focused.
- VulnCheck: Modern vulnerability intelligence platform offering real-time exploit and vulnerability prediction data. Comparable as a vulnerability intelligence provider focused on emerging threats, with a more technology-driven, less community-moderated model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks4 records
Key highlights6 records
Customer concentration
SecurityFocus social profiles
Digital presenceSecurityFocus financial estimates
Financial estimateRevenue estimate
Valuation estimate
SecurityFocus leadership team
Management profileNumber of profiles
SecurityFocus funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SecurityFocus M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SecurityFocus
What does SecurityFocus do?
SecurityFocus operates a platform of two curated, moderated mailing lists for the security research community. The flagship Bugtraq list (founded 1993) provides vulnerability disclosure and security advisories across proprietary, open source, hardware, firmware, and embedded systems targets. Bugtraq AI is a newer list dedicated to vulnerability disclosures and security research focused on AI/ML systems, covering model exploits, inference attacks, training data poisoning, framework vulnerabilities, and adversarial machine learning. Both lists accept open submissions from security researchers worldwide and are accessible via public archives.
Is SecurityFocus a public or private company?
SecurityFocus is a private company. It is classified as unknown and is currently operating.
When was SecurityFocus founded?
SecurityFocus was founded in 1993. It employs 251 to 500 people.
Where is SecurityFocus based?
SecurityFocus is headquartered in Mountain View, United States, in the North America region.
How does SecurityFocus make money?
One revenue line is on record: community Mailing List Services.
Who are SecurityFocus's main competitors?
Broad incumbents on record are Tenable, Qualys, Rapid7 and NVD (National Vulnerability Database). Direct peers are Bugcrowd, MITRE Corporation (CVE Program), HackerOne and Seclists (Full Disclosure). Emerging players are Openwall Project and VulnCheck.
Does SecurityFocus have an API?
No public API is recorded for SecurityFocus.
What industry is SecurityFocus in?
SecurityFocus's product category is Vulnerability Disclosure Services. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction, with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 54151 and its SIC code is 7370.