According to Foresight News, Bitcoin Core developers have developed a new "critical vulnerability" disclosure policy. Core developer Antoine Poinsot said that the new policy will better communicate the risks of running outdated versions of Bitcoin Core and provide a standardized disclosure process that will give researchers more motivation to discover and disclose vulnerabilities responsibly. This will help prevent future security vulnerabilities because security vulnerabilities will be made available to a wider group of contributors.
The new disclosure policy will classify vulnerabilities according to four levels of severity: low severity (difficult to exploit, low impact vulnerabilities); medium severity (limited impact vulnerabilities, such as remote collapse of the local network); high severity (potentially significant impact); and critical severity (threat to the integrity of the entire network).