I have a few #infosec questions...
1) Under what circumstances are SEC filings required when a company is notified of a vulnerability?
2) What are the consequences of lying about the severity in such a report?
Asking for a friend. Who is me. In Minecraft.