Risky Bulletin Newsletter
July 01, 2026
Risky Bulletin: Researcher drops giant cache of zero-day exploits
Presented by
News Editor
An anonymous security researcher going online by the pseudonym of Bikini has published proof-of-concept exploit code and detailed write-ups for more than a dozen zero-day vulnerabilities in popular open-source projects.
The exploits were published without notifying any of the vendors.
They impact 15 software projects, including some big names like the Linux kernel, Libssh2, Anydesk, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN, the VLC player, and more.