Covers hypothesis-driven vulnerability discovery, reproducible proof of concept, impact analysis, vendor coordination, embargoes, and responsible public disclosure.