What We Know
An anonymous GitHub account using the handle “bikini” published a repository named Exploitarium that collects a large set of previously undisclosed proof‑of‑concept (PoC) exploits. Reporting summarizes the collection as roughly 130+ PoCs spanning about 22 different software projects and notes the poster did not notify vendors before release; two of the published items have been described as critical in one writeup.
Community reviewers have begun looking through the submissions. A Hacker News commenter who inspected the Ghidra‑related entries found some of those PoCs unimpressive and noted at least one requires being able to overwrite local binaries in a development toolchain, which limits its practical exploitability. A Dev.to post and other writeups are guiding readers through the repository and raising discussion about the releases. The GitHub repository itself is publicly accessible at the linked Exploitarium page.
Source Comparison
Aligned reportingCorroborates
- github.com↗The public GitHub repository 'bikini/exploitarium' exists and hosts the collection, corroborating that the exploitarium is publicly accessible on GitHub.
- Hacker News↗A Hacker News commenter who inspected the Ghidra-related entries called some PoCs unimpressive and noted at least one requires overwriting local binaries in a Swift toolchain, limiting practical exploitability.
- byteiota.com↗A writeup reports an anonymous 'bikini' account released roughly 130+ unpatched PoC exploits across about 22 projects without notifying vendors and notes two of the published items as critical.
- dev.to↗A Dev.to post walks readers through the anonymous mass release, providing guidance and discussion about the repository and its contents.