Exploitarium Dropped 204 Live Exploits for curl libssh2 and Nmap With No Warning
Someone published 204 exploit files on GitHub for software you almost certainly use, and told the vendors nothing. The makers found out the same way the attackers did, by reading the page. π§
The account goes by bikini. The project is called exploitarium, a single archive of ready-to-run exploit code for software that sits underneath much of what you use. The first dated entries go back to June 23, and by June 27 the page was pulling in stars and hundreds of comments, which meant defenders and attackers were reading the same exploits at the same moment.