Researcher Publishes Over 30 Zero-Day Exploits Without Prior Disclosure (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Over 30 zero-day exploits for open-source projects released without prior notification
- AI-assisted fuzzing using GPT models claimed by researcher
- CVE-2026-55200 (libssh2, CVSS 9.2) independently verified and actively exploited
"A pseudonymous security researcher released over 30 proof-of-concept exploits for zero-day vulnerabilities in open-source projects on GitHub without informing maintainers first. Affected projects include the Linux kernel, FFmpeg, 7-Zip, VLC, and others. The researcher claimed to have used AI models for fuzzing. Some vulnerabilities have since been assigned CVEs and partially patched. The action sparked debate over coordinated disclosure practices."
no comments yet.