Tech News
← Home  ·  All topics

Vulnerability Disclosure

3 GoKawiil briefs on this topic

Radicle discloses two critical flaws in its peer-to-peer network protocol

Radicle disclosed two critical security vulnerabilities affecting every released version of its code collaboration stack: network traffic between nodes is unencrypted and can be read by anyone observing the path, and the connection handshake's peer authentication can be bypassed. Security researcher Konstantinos Maninakis reported the encryption issue on June 24, 2026, prompting the disclosure.

Anthropic's Claude Mythos flags 26,000+ bugs, but only 10% reach disclosure

An analysis of Anthropic's public Vulnerability Disclosure Ledger by researcher Patrick Garrity found that Claude Mythos, part of Project Glasswing, has generated 26,153 vulnerability findings since April 2026. Of those, only about 2,736 have entered the disclosure pipeline, roughly 202 have been patched, 245 withdrawn, and 191 await initial reporting to maintainers, leaving nearly 90% of findings unprocessed.

EU Cyber Resilience Act's 24-hour breach reporting deadline arrives September 2026

An open-source maintainer describes receiving an extortion attempt disguised as a bulk vulnerability report—95 claimed flaws, only two or three real—followed by a $100,000 ransom demand threatening public disclosure. He argues this scenario foreshadows a legal reality coming for far more companies: starting September 11, 2026, the EU Cyber Resilience Act requires any manufacturer selling connected products into the EU to notify ENISA within 24 hours of learning that a vulnerability in their product is being actively exploited.