Skip to content
Exploitarium: Anonymous security researcher publishes two dozen zero-days

Exploitarium: Anonymous security researcher publishes two dozen zero-days

Heise.De July 1, 2026

An unknown individual with the summery pseudonym “Bikini” has published proof-of-concept code for nearly two dozen security vulnerabilities on the code-sharing platform GitHub – all of which, according to their statement, are previously unfixed zero-days. Among them are exploits for PHP, OpenVPN, VLC, and other projects. The severity of the vulnerabilities ranges from information leaks to code injection. Anyone who wishes can report the vulnerabilities to the manufacturer to gain fame.

In the GitHub repository “ Exploitarium ,” all vulnerabilities can be found with a short README, which, like parts of the actual vulnerability discovery, is AI-generated. The following projects are affected individually:

As the unknown security researcher himself writes, some of his findings are “a bit shoddy,” while others are better. He used AI for assistance in finding vulnerabilities but emphasizes that almost all PoCs are hand-coded. Except for one vulnerability – CVE-2026-55200 –, there are no CVE identifiers, CVSS scores, or other additional information. Potentially affected parties must extract these from the respective readmes and the PoC code or wait for processing by the manufacturers. The podcast “Passwort” goes into detail the backgrounds of CVE, CVSS, and other metadata for security vulnerabilities in its current episode.

Mit Ihrer Zustimmung wird hier ein externer Podcast (Podigee GmbH) geladen.

Ich bin damit einverstanden, dass mir externe Inhalte angezeigt werden. Damit können personenbezogene Daten an Drittplattformen (Podigee GmbH) übermittelt werden. Mehr dazu in unserer Datenschutzerklärung .

The motivation behind Exploitarium is recruitment, writes the Anonymous. He is gifting the findings to the public and emphasizes that anyone may report them to the affected manufacturers to “collect” a CVE for them. The security researcher decided on this approach to “lure people into the field [of exploit hunting, editor's note],” considering it the “most efficient way” of recruitment.

AI-generated security vulnerabilities have been flooding the bug bounty programs of many manufacturers in recent months in a kind of “Vulnocalypse,” leading to noticeable signs of wear. The cURL project has therefore declared the “ Summer of Bliss ” and will not process bug reports in July.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities