Alby warned of a critical flaw in older versions of Alby Hub, a self-hosted Bitcoin Lightning wallet that people run on their own computer or server to hold their funds. An attacker who could reach the wallet's management interface over the internet could gain access without permission and send the owner's funds. The flaw affects versions 1.7.0 through 1.18.5, released before August 2025, and was fixed in 1.19.0 and later, with 1.24.0 the current release. Alby says one user has been affected so far and is withholding technical details for now. The core lesson is to never expose a self-hosted wallet's control interface to the public internet.
SonicWall released emergency firmware updates for Gen 6, Gen 7, and Gen 8 firewalls after CrowdStrike's research team disclosed three SonicOS flaws on April 29. The worst is CVE-2026-0204 (CVSS 8.0), a weak authentication bug in the management interface that lets an attacker on an adjacent network reach management functions without logging in - and from there change firewall rules, disable security protections, or open new holes. The other two are post-authentication: CVE-2026-0205 is a path traversal that breaks out of restricted directories, and CVE-2026-0206 is a buffer overflow that crashes the firewall. No public exploits yet.