What we will not publish
Where the line sits on exploit material.
We do not publish working exploit code, payloads, or the steps that turn a flaw into a weapon.
Explaining a class of bug is journalism and we do it: what deserialisation is, why an authentication bypass in a management interface is worse than one in a user portal, what makes a flaw wormable. That is the part a defender needs.
The payload is not that part. A defender-facing site does not only have defenders reading it, and the half that is useful for defence is not the half that is useful for attack. Detection logic, indicators of compromise, log queries and mitigations are all publishable, and are what we carry instead.
Where a proof of concept is already public and its existence changes your urgency, we will say that it is public and link to the vendor or agency saying so. We will not reproduce it.