A group of hackers claims to have discovered a new vulnerability in the latest version of OpenSSL. They claim to have found a security flaw that is similar to the now-infamous Heartbleed bug in OpenSSL 1.0.1g, but experts are questioning their claims.
They haven't published the exploit, which appears to be written in Python, but they are confident they can increase their own profit by exploiting the vulnerability for a long time before it is patched.
On the other hand, they are willing to sell it for 2.5 Bitcoins ($780/€1,069) or 100 Litecoins ($973/€725).
We don't know much about the group advertising the exploit. Their contact email address is BitWasp@safemail.net.
The only evidence they have is a screenshot showing what the response from a server looks like. However, that doesn't prove much, and security experts are skeptical about the hackers' claims.

