Organizations are increasingly adopting open source and unified threat management (UTM) firewall solutions to strengthen network security, improve flexibility, and reduce costs. Open source firewalls provide transparency, allowing security teams to audit and customize the codebase, while also offering advanced features such as stateful inspection, deep packet inspection, VPN support, and integrated intrusion detection/prevention systems. Community-driven development ensures frequent updates and reliable support, making these solutions attractive for modern infrastructure protection. UTM firewalls, on the other hand, consolidate multiple security functions—including firewall, IDPS, antivirus, anti-spam, VPN, and web filtering—into a single platform, simplifying management and providing comprehensive protection, especially for small and medium-sized businesses.
Recent developments include the release of IPFire 2.29 Core Update 199, which introduces support for the latest Wi-Fi standards, updates to the integrated Suricata intrusion prevention system, kernel upgrades for improved stability and security, and mitigations for proxy-related vulnerabilities. These enhancements reflect the ongoing evolution of open source firewall platforms to address emerging threats and operational requirements. As remote work becomes more prevalent, open source remote desktop solutions are also gaining traction, offering secure, flexible access with the added benefit of code transparency for security audits and policy alignment.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
IPFire released version 2.29 Core Update 199 with new firewall and network features, including Wi-Fi 6/7 support, LLDP/CDP support, a Linux 6.12.58-based kernel, and Suricata 8.0.2 updates. The release also improved OpenVPN handling, mitigated a proxy-related vulnerability, and included multiple package and security library updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
blog.comodo.com
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.