Security vulnerabilities responsible disclosure reported

I’m a security researcher. Summary of where things stand:

• 10 june 2026 — Vulnerability report affecting the main Kimi chat interface sent to [email protected]
• Today — 60+ days elapsed, no acknowledgment, issue appears unresolved

I’ve used the channel your security team designates in the earlier VDP thread here.

What I need is a reply. Specifically: confirmation of receipt, a secure route for the technical details, and a safe harbor statement covering the testing already done.

So that expectations are clear on both sides, I’m following standard coordinated disclosure practice.

No technical details in this post.

Reachable by DM here.