August 23, 2026
- Monero GUI published a batch of disclosures fixed in v0.18.5.0, including a Windows installer that left the
p2pooldirectory world-writable (local binary planting to code execution) (HackerOne) and amonero://deeplink parsing flaw that let crafted links trigger send-all transactions (HackerOne). Also disclosed: an OpenAlias resolver that autofills addresses despite failed DNSSEC validation, and a multisig double-spend via withheld partial signatures. · Vulnerabilities & Exploits
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick