Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux
STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets
Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

GIMP: APNG Integer Overflow Enables Code Execution, Patch Released
An integer overflow in GIMP's APNG parser allows remote arbitrary code execution when a user opens a malicious file. Tracked as CVE-20…

GStreamer RCE Bug in MRF Parsing: Urgent Update Required
An out-of-bounds write vulnerability in GStreamer's MRF file parser enables remote code execution. User interaction is required, but t…

Tengu: The Botnet That Turns Reboot Into a Forensic Trap
Discovered by Nozomi Networks Labs, the Mirai variant Tengu abuses the hardware watchdog timer on embedded Linux devices to force an a…

OpenWrt: A '90s-Era Buffer Overflow Opens Routers to Remote Takeover
A critical flaw in OpenWrt's DHCPv6 server allows pre-authentication remote code execution on routers. A public proof-of-concept explo…

Samsung rlottie: RCE Bug in Lottie Animations, Patch Available Since July 3
The open-source Samsung rlottie library contains a numeric truncation vulnerability (CVE-2026-15551, CVSS 5.5) enabling remote code ex…

X.Org Server: Critical Glamor Font Bug Allows Root Privilege Escalation
CVE-2026-55999 in the Glamor Font component of X.Org Server and Xwayland lets any local user with an X connection escalate to root. Pa…

LiteLLM Open-Source LLM Gateway Distributes Credential-Stealing Malware
Two PyPI versions of the litellm package were compromised by malware that abuses Python .pth files to exfiltrate credentials to an att…

SleeperGem: The Day RubyGems Became an npm-Style Target
Three malicious RubyGems packages compromised developer workstations through require-time execution and CI evasion. The campaign marks…

CVE-2026-3888: LPE to Root in snapd Hits Ubuntu LTS Since 2016
Qualys discovered a local privilege escalation vulnerability in snapd that lets a local attacker gain root on Ubuntu 16.04 through 24.…

ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Enables Local Privilege Escalation at CVSS 8.8
An integer overflow in the Linux kernel's vmwgfx graphics driver allows local privilege escalation to kernel context. Published July 1…