CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Researcher drops giant cache of zero-day exploits

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 165

As cited

Copy frozen at (site build).

vulnerabilities

Risky Bulletin: Researcher drops giant cache of zero-day exploits

A researcher using the pseudonym Bikini published proof-of-concept exploits and technical details for over a dozen zero-day vulnerabilities in popular open-source and commercial software without notifying vendors beforehand. The affected projects include the Linux kernel, Libssh2, Anydesk, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN, and VLC player, among others.

Why it matters: Organizations using any of the 15 affected software projects face immediate exploitation risk; security teams should prioritize assessment of their exposure to these vulnerabilities and begin developing mitigation strategies while patches may still be unavailable.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: Researcher drops giant cache of zero-day exploits

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: Researcher drops giant cache of zero-day exploits

An anonymous researcher using the alias Bikini released proof-of-concept exploits and technical details for over a dozen zero-day vulnerabilities. The affected projects include widely used open-source software such as the Linux kernel, Libssh2, Anydesk, and PHP, among others. Vendors received no prior notification before the public disclosure.

Why it matters: Organizations using these open-source projects face immediate risk of exploitation and should prioritize mitigation or patching.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Risky Bulletin: Researcher drops giant cache of zero-day exploits

An anonymous researcher using the alias Bikini released proof-of-concept exploits and technical details for over a dozen zero-day vulnerabilities. The affected projects include widely used open-source software such as the Linux kernel, Libssh2, Anydesk, and PHP, among others. Vendors received no prior notification before the public disclosure.

Why it matters: Organizations using these open-source projects face immediate risk of exploitation and should prioritize mitigation or patching.

VendorsLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary