An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them.
The archive, hosted under the name “exploitarium” by a researcher using the handle “bikini,” turned coordinated disclosure on its head by publishing exploit code first and leaving vendors and defenders to catch up in public.
What initially looked like a short‑lived spike in attention has instead evolved into a growing repository that continues to add new vulnerable projects week after week.
The exploitarium archive started to take shape in late June 2026, with dated entries appearing from June 23 and a first large public batch drawing heavy traffic around June 27.
As issues and pull requests piled up, the repository’s README made clear that none of the findings had been reported to affected vendors ahead of time, and explicitly encouraged others to claim credit by disclosing them independently.
Analysts from LevelBlue SpiderLabs noted that this approach put exploit code in front of attackers and defenders simultaneously, erasing the protective window that coordinated disclosures are designed to provide.
Since that initial burst of attention, the project has continued to expand while most public coverage moved on.
LevelBlue said in a report shared with Cyber Security News (CSN) that the new folders have landed at a steady pace of roughly two to three per week, including recent additions against widely deployed platforms such as PostgreSQL, Redis, Nextcloud, and Discourse in the first week of July alone.
Illustration of the pre-fix size computation (Source – LevelBlue)
Behind the headline number of “130 PoCs” cited in early reporting, SpiderLabs’ count now shows 35 tracked project folders with 204 files, reflecting just how much research has been folded into the archive after the first stories were published.
Illustration of the upstream fix (commit 97acf3d) (Source – LevelBlue)
The attack surface exposed by these PoCs spans far more than a single stack or vendor. Native C and C++ codebases, kernel drivers, web application logic, remote‑access tools like AnyDesk and RustDesk, and core infrastructure such as Nmap and curl all appear in the inventory.
This breadth turns the incident into a supply chain problem as much as a vulnerability story, since many organizations may inherit exploitable libraries as transitive dependencies without realizing they are there.
Anonymous Researcher Dumps 204 0-Day Exploit Files
The anonymous drop closely matches a pattern that LevelBlue had already seen this year in the Nightmare‑Eclipse campaign, but with a wider and more systematic reach across open‑source ecosystems.
Whereas Nightmare‑Eclipse zeroed in on a single vendor and Windows internals, exploitarium pushes mass disclosure into developer tools, cloud‑ready services, container platforms, and community forums.
For readers who followed earlier coverage of Windows Defender exploitation, the RoguePlanet articles on new Windows Defender 0‑Day exploit RoguePlanet and RoguePlanet Defender patch claim may leak data show how quickly uncoordinated drops can translate into complex operational risk.
External contributor adds new vulnerability research via Pull Request #4 (Source – LevelBlue)
Within exploitarium, not every folder carries the same weight, and LevelBlue’s assessment stresses that defenders should avoid treating the entire archive as uniformly critical.
Many entries look like low‑impact artifacts from automated fuzzing runs, while others document high‑severity, pre‑authentication flaws in widely embedded components.
A standout example is CVE‑2026‑55200 in libssh2, an out‑of‑bounds write in the ssh2_transport_read function that can be triggered before any SSH authentication completes, potentially enabling remote code execution against vulnerable clients.
Cyber Security News (CSN) previously covered this bug in detail in its piece on the critical libssh2 vulnerability allows attackers and a follow‑up on the PoC exploit released libssh2 RCE vulnerability, showing how a single entry from the archive can ripple quickly into real‑world attack scenarios.
The libssh2 case also illustrates the messy overlap between coordinated and uncoordinated disclosure.
While exploitarium included a libssh2 PoC from day one, the official CVE credit went to researcher Tristan Madani through VulnCheck’s normal reporting channels, meaning the same underlying defect surfaced through both responsible and mass disclosure paths.
For defenders, that nuance matters less than the practical takeaway: track the upstream fix, migrate to a version that incorporates commit 97acf3d, and treat the vulnerability’s broad transitive footprint as a priority regardless of whether exploitation has been confirmed.
From solo archive to shared risk
Over time, exploitarium has shifted from a personal archive to a lightly moderated clearinghouse that accepts outside research.
LevelBlue points to contributions such as Pull Request 4 from the user “Unrealisedd,” which introduced new Windows kernel driver issues in OpenVPN’s ovpn‑dco‑win component, complete with suggested remediations.
The maintainer also retroactively credited external work on objdump, acknowledging that another researcher had published a more complete PoC separately before the finding was folded into the archive.
For organizations that worry about provenance, this blend of careful Git‑tree verification and informal contributor vetting means exploitarium now amplifies unvetted code with the implicit credibility of its growing collection.
The README details a rigorous provenance verification process (Source – LevelBlue)
LevelBlue’s guidance to security and detection teams centers on pragmatic triage under pressure. Patch first and rank items by reachability and blast radius, not by media attention or proof‑of‑concept novelty alone.
They recommend running software composition analysis across build pipelines, container images, and vendored libraries to find hidden libssh2 dependencies and other embedded components touched by the archive.
In parallel, they highlight community efforts like the Exploitarium‑Detections project, which publishes KQL rules for Microsoft Sentinel and Defender XDR to spot activity associated with the disclosed vulnerabilities.
For organizations already tracking recent supply chain incidents such as the Mastra npm packages compromised attack, exploitarium should be read as part of the same broader trend: research repositories that can instantly shift theoretical zero‑days into accessible attack kits.
LevelBlue’s report underscores that exploitarium is “not a discrete incident with a start and end date” but an ongoing infrastructure likely to keep generating both genuine findings and triage overhead for as long as it is maintained.
The maintainer has already paired the archive with a general‑purpose code‑obfuscation toolkit, underlining that this is an active research pipeline rather than a one‑off disclosure stunt.
For executive teams, the recommended framing is closer to a long‑tail supply chain exposure than a single vulnerability, demanding sustained monitoring, rapid patch adoption, and continual reassessment of which open‑source components are quietly bundled into critical workloads.
Indicators of Compromise (IoCs):-
TypeIndicatorDescriptionProject folderlibssh2-cve-2026-55200-pocProof‑of‑concept archive for CVE‑2026‑55200 affecting libssh2.Project folderobjdump-dlx-calc-pocLarge objdump exploit collection with 41 tracked files.Project folderrustdesk-session-permission-pocsRustDesk session permission exploit set with 17 tracked files.Project folderovpn-dco-win (Windows kernel driver)OpenVPN Windows kernel‑mode driver vulnerabilities added via PR 4.Project foldernmap-ipv6-extlen-wrap-pocNmap IPv6 extension length wrap exploit project folder.Project folderpostgres-ri-owner-switched-cast-pocPostgreSQL referential integrity owner switch exploit folder.Project folderredis-vset-duplicate-hnsw-id-rce-pocRedis RCE via vset duplicate HNSW ID exploit project.Project foldernextcloud-federated-share-bearer-token-pocNextcloud federated share bearer token abuse exploit folder.Project folderdiscourse-scoped-api-key-preauth-bypassDiscourse scoped API key pre‑authentication bypass folder.Project folderfirefox-smartwindow-private-url-exfil-pocFirefox Smart Window private URL data exfiltration exploit project.
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an
The post Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them appeared first on Cyber Security News.



