Skip to main content

GlobaLeaks strengthens security against AI-enabled threats: New audit reflects evolution of cyberattacks

Today, we are publishing the results of a new independent Source Code Audit under an LLM-Equipped Adversary Model conducted by ISGroup, further demonstrating our commitment to transparency and continuous security improvement.

This latest assessment represents a significant evolution in security testing: by combining human expertise with AI-assisted code analysis, researchers were able to examine the codebase with an unprecedented level of speed and coverage.

The review demonstrates how Large Language Models (LLMs) are reshaping the field of security research, making it possible to perform exhaustive code analysis at a record pace and a scale that was previously impractical. While this evolution presents new challenges for software developers, we see it also as a necessary step that raises the security standard across the industry.

The independent security assessment by ISGroup from June 1 to June 30, 2026 as well as many contributions from our community members and GlobaLeaks users led to identifying 29 confirmed vulnerabilities, alongside 12 denial-of-service observations and additional hardening recommendations.

As expected for an extensively audited codebase, the vast majority of findings were classified as Low or Informational, with only two High-severity issues and no critical vulnerabilities. The confirmed findings primarily concerned account protection mechanisms, whistleblower anonymity safeguards, tenant isolation, audit logging completeness, and service availability under specific conditions.

The review was conducted on a development snapshot captured during an intensive hardening cycle, and all identified issues have since been addressed as part of our ongoing secure development process. All confirmed vulnerabilities were remediated starting with version 5.0.96, released on June 24. As always, we strongly recommend keeping your GlobaLeaks installation up to date by running the latest stable release, which is currently version 5.0.99.

The results of this effort highlight the value of continuous security assessment with particular attention to emerging technologies that impact software security. Even a platform that has been repeatedly audited over more than a decade can benefit from an AI-assisted security audit leveraging the same tools used by attackers today to find vulnerabilities. We would like to call the open source community to come together to address the new security challenges facilitated by generative AI and think critically about how we can ethically integrate AI-powered tools, where it has become crucial for the protection of our users.

We will continue investing in independent security research, rapid remediation, and transparent disclosure to ensure that GlobaLeaks remains one of the most secure and thoroughly audited open-source whistleblowing platforms available.

Lastly, we would like to sincerely thank the auditors’ team for their professionalism, technical expertise, and collaborative approach throughout this assessment as well as GlobaLeaks community members for their active contributions to keep the software safer in the AI era.

The full report is available for download here.