After being informed of vulnerabilities in Newscoop by High-Tech Bridge SA, we’ve released two updates - Newscoop 3.5.5 and Newscoop 4 RC4.
The vulnerabilities affect all versions of Newscoop prior to 3.5.4 and upgrade should be applied as soon as possible.
It also affects any development, beta or RC versions of Newscoop 4.0 (up to RC3) - for these sites, immediate upgrade to Newscoop 4 RC4 is recommended. This is not an official stable release yet and not recommended for production servers. We also sneaked some other improvements and bug fixes into this release (here's the full changelog).