News linked to both this project and an event.
Odaily News: Bitcoin News posted on X platform that Core Lightning version 26.06.7 has been released, fixing multiple vulnerabilities that were responsibly disclosed over the past three weeks. Recently, there has been an increase in AI-generated security reports targeting open-source Bitcoin projects. Specific vulnerability details will be kept confidential for two weeks to allow node operators to complete upgrades before technical details and source code are published. Developers warned that immediately disclosing the fixes could allow attackers to reverse-engineer the vulnerabilities and attack nodes that have not yet been updated. All Core Lightning node operators should upgrade immediately. Docker images are not yet available, and developers have explicitly warned users not to wait for the Docker image.
Bitcoin payment processing service BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running Lightning Network Daemon (LND) software. Attackers exploited a severe vulnerability to obtain credentials and transfer funds. The number of affected operators and the total amount stolen have not yet been disclosed. This restriction affects external wallets such as Zeus that connect via BTCPay Server domains or Tor onion addresses in Docker deployments, but Lightning Network payments can still continue. BTCPay Server stated that remote access functionality will be restored once security is confirmed. BTCPay Server 2.4.2 will install LND 0.21.1 and automatically regenerate macaroon credentials during standard installation. Foundation and Citadel21 have respectively disclosed that funds from their Lightning Network nodes were swept. Foundation stated that hot wallets were not affected, and the specific amounts of losses have not been disclosed.