{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreifry2j3lhnywhrjg3f6eb27xrqohi4vspau75xlcyunmjlrwwdc6u",
"uri": "at://did:plc:haakkg7y3xdghcdmprxeexso/app.bsky.feed.post/3mnapi75mycv2"
},
"path": "/t/forward-emails-security-audit-by-cure53-is-live/38280#post_3",
"publishedAt": "2026-06-01T17:28:33.000Z",
"site": "https://discuss.privacyguides.net",
"textContent": "It is promising that they published this but damn those were some serious vulnerabilities.\n\nAlso think this is important:\n\n> The limited timeframe of FWD-01, however, did not make it possible for Cure53 to cover as much of the ecosystem as desired.\n>\n> In particular, the mail stack and the internal services received only cursory attention relative to the web and API. For this reason, Cure53 strongly recommends continued retesting of the in-scope components in future engagements, as these are needed to maintain and extend the existing security posture observed during this initial May 2026 inspection.\n\nFor me personally it would not be mature enough. The fact they got this done is super positive don’t get me wrong, but the findings in the limited timeframe would leave me thinking more security improving and testing is needed.\n\nIt would be fair to say these vulnerabilities are not uncommon at big providers either. But larger companies have dedicated security teams to make sure these things are solved quickly, rather than priotizing speed to market and fixing things after pentest.",
"title": "Forward Email's security audit by Cure53 is live!"
}