Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

Anonymous researcher dumps zero-day exploits for multiple software products

An anonymous researcher has publicly released exploit code for multiple zero-day vulnerabilities, including a critical pre-authentication remote code execution flaw in libssh2 (CVE-2026-55200, CVSS 8.1) and an authentication bypass in Gitea Docker deployments (CVE-2026-20896). The libssh2 vulnerability affects versions up to and including 1.11.1, with a fix merged in the project's repository, while Gitea has released patches. The public availability of these exploits, some already under active attack, significantly increases the risk of widespread exploitation, necessitating immediate patching.
Read Full Article →

Vulnerability Management Anonymous researcher dumps zero-day exploits for multiple software products June 30, 2026 Share By SC Staff (Adobe Stock) The Register reports that an anonymous researcher, known as bikini, has released exploit code for zero-day vulnerabilities affecting at least 15 software products and open-source projects without prior vendor notification. At least two of these vulnerabilities are already being actively exploited by attackers. The disclosed exploits include a critical pre-authentication remote code execution vulnerability in libssh2 (CVE-2026-55200) and an authentication bypass vulnerability in self-hosted Gitea Docker deployments (CVE-2026-20896), which allows attackers to impersonate users and take over Git servers. A fix for libssh2 is merged, and Gitea has released patches. The researcher, who claims to have used AI models like GPT-5.5 Codex for vulnerability discovery, published the exploits in a now-removed GitHub repository. While some findings have been dismissed as low-impact, the libssh2 and Gitea vulnerabilities have been independently verified as high-risk. The public release of these exploits, without vendor notification, raises concerns about potential widespread attacks, especially as attackers can now leverage these proofs-of-concept without needing to develop their own exploits. Source: The Register SC Staff Related Vulnerability Management Critical Oracle E-Business Suite bug actively exploited Steve Zurier June 30, 2026 Critical Oracle EBS flaw now exploited, prompting urgent patching guidance. Patch/Configuration Management Microsoft extends Windows Server 2022 hotpatching to 2027 SC Staff June 29, 2026 Microsoft will continue to offer hotpatching for Windows Server 2022 Datacenter: Azure Edition until 2027, a move that extends support beyond the mainstream end date of October 13, 2026. Vulnerability Management Deloitte joins IBM and Red Hat’s initiative to secure open-source software SC Staff June 29, 2026 The partnership focuses on strengthening the security of open-source components used in enterprise software. Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article