Researcher publishes proof-of-concept exploits for dozens of open-source zero-days including FFmpeg, OpenVPN, VLC, 7-Zip, and Ghidra

A researcher has publicly released proof-of-concept exploit code for dozens of previously unknown vulnerabilities in widely used open-source software, raising the risk of copycat attacks before many users have fixes. SecurityWeek says the disclosures affect projects including FFmpeg, OpenVPN, VLC, 7-Zip, Ghidra, Gogs, and Gitea, and that nine of the flaws have CVE identifiers so far. The researcher said the bugs were found with large-language-model-assisted fuzzing, an automated bug-hunting technique.
Why it matters: This matters because public exploit code can sharply speed up real-world attacks against unpatched systems and developer tools. Organizations using the named projects should urgently inventory exposure, watch for vendor advisories and patches, and consider temporary mitigations or isolation for internet-facing deployments.

Sources

In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
SecurityWeek News 2026.07.03 100% relevant
This article is the first item here establishing the broader event: a mass public release of open-source zero-days spanning multiple popular projects, beyond any single previously tracked product-specific flaw.
← Back to all stories