Cryptocurrency prices are highly volatile. All content is for reference only and is not investment advice. Trading involves risk of total loss.

Full disclaimer
Back to News
SourceCointelegraph

Core Lightning confirms multiple vulnerabilities, prepares security update

Core Lightning advised operators to use offline mode if they do not install the forthcoming update, keeping their nodes active but disconnected.
Disclaimer: The views above are the author's only and do not represent 711BTC. Nothing here constitutes investment advice.

Related

09-16 18:53

Bitcoin Core Software Update Aims for Speed and Security Patches

Bitcoin Core 32.0 has entered final testing, bringing faster block checks and changes to how wallets prepare payments.

06-30 01:08

The culprit behind the exhausted Codex credit limit has been identified; OpenAI has fixed multiple vulnerabilities and implemented a third round of full-scale compensation resets.

According to Beating's monitoring, the cause of the abnormal consumption of credit limits in Codex, a programming intelligence agent under OpenAI, has been officially identified. Tibo Sottiaux, the core product manager, announced that the team has deployed a patch to fix the issue across all users. In addition to resetting the credit limits for all users, all users will also receive an additional reset card valid for 24 hours. The excessive consumption was not caused by a single vulnerability, but by a combination of multiple minor backend issues and display false alarms. At the operational level, the system's automatic review was too frequent, unexpectedly triggering too many sub-agent tasks, and the backend suggestion function repeatedly ran and retried after failure, consuming tokens exponentially. At the display level, automatic review was incorrectly classified as GPT-5.4 consumption, and failed or rate-limited requests were also incorrectly displayed as credit consumption in the frontend charts, directly causing a credit shortage for all users. Currently, the official team has deployed a hotfix patch simultaneously on the billing backend, desktop client, and CLI terminal. In addition to resetting the credit limits for all users, only successful interaction requests will be recorded in the Turn statistics chart in the future. Although the erroneous data in the historical charts cannot be changed, the actual token consumption after the update will be significantly reduced.

06-29 02:45

SlowMist: curl fixes 18 security vulnerabilities; it is recommended to upgrade curl/libcurl as soon as possible and check for related risks.

PANews reported on June 29th that 23pds, Chief Information Security Officer of SlowMist, published an article on the X platform stating that curl recently patched 18 security vulnerabilities, involving authentication bypass, memory safety, and host verification issues. One of these vulnerabilities in libcurl had existed for approximately 25 years. The risks are not limited to the curl command line but also widely affect applications, SDKs, containers, firmware, gateways, and CI/CD environments that rely on libcurl. It is recommended to upgrade curl/libcurl as soon as possible and check whether older versions of libcurl are being used, paying particular attention to mTLS, proxy authentication, and connection multiplexing scenarios.

06-26 03:13

Meta acquires the co-founders and core team of AI security startup Virtue AI.

According to Beating's monitoring, Meta has recruited three co-founders and the core team from Virtue AI, an AI security and governance startup. The three founders are Dawn Song, a professor at UC Berkeley; Bo Li, an associate professor at the University of Illinois at Urbana-Champaign; and Sanmi Koyejo, an assistant professor in the Department of Computer Science at Stanford University. Meta is only absorbing the team; it is not acquiring Virtue AI as a company entity, nor is it involved in intellectual property or customer contracts. Founded in 2024, Virtue AI focuses on enterprise-grade AI security infrastructure, developing automated red team testing, runtime guardrails, and agent security governance tools. Meta plans to enhance the protective capabilities of autonomous software agents against security vulnerabilities such as data breaches and malicious commands by bringing in the team. Dawn Song will become the Vice President of Research at Meta AI. She and Bo Li will join Meta Superintelligence Labs (MSL), reporting directly to head Nat Friedman, ensuring that security research stays aligned with cutting-edge model development. Sanmi Koyejo will join the Meta FAIR (Fundamental AI Research) lab, reporting to lab director Rob Fergus. Previously, Virtue AI received early support from Lightspeed Venture Partners, Walden Catalyst Ventures, Prosperity7 Ventures, Factory, Osage University Partners (OUP), and Liwu Chen, among other institutions and investors.

06-25 04:32

Taiko has released a security incident update: Testing of the remediation plan has begun, and full collateralization of bridged assets will be completed before restarting.

PANews reported on June 25th that Taiko, an Ethereum Layer 2 project, released an update on the security incident, stating that the incident will not result in any user fund losses. Currently, the bridged assets are undercollateralized, and all collateral will be replenished before the bridge reopens to ensure that every user's balance is backed 1:1, exactly as before the incident. Since the incident, Taiko has taken cautious measures, including controlling the scope of the impact, determining the cause of the incident, and collaborating with the board of directors to develop a plan to protect user assets. Furthermore, Taiko's CEO has submitted a formal report to the relevant authorities in Singapore, and the team will fully cooperate in investigating those responsible.

06-24 00:40

Anthropic's Mythos system detected security vulnerabilities in US infrastructure.

According to Mars Finance, on June 24, the Associated Press reported that Anthropic's Mythos system detected security vulnerabilities in US infrastructure.