frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Anonymous GitHub account mass-dropping undisclosed 0-days

https://github.com/bikini/exploitarium
56•binyu•1h ago

Comments

functionmouse•28m ago
we have got to stop putting our bank accounts and SSNs on computers
merelydev•27m ago
Most of the exploits are for opensource/free software.

I don't know what methods where used to find these exploits but I am starting to think security through obscurity might not be a bad thing in this day and age, where someone can just let bots loose on your codebase.

serf•22m ago
llms are fantastic disassembly partners, they're quite good at labeling functions from various dissassemblers -- the net losses from losing the benefits of open source , imo , outweigh the protection afforded by hiding your source code in yet another layer that is more and more easily unrolled through automated procedures.
spongebobstoes•16m ago
disassembly only applies to client side software

something like nginx could arguably be more secure if it was closed source

(I am a proponent of and contributor to open source)

gpm•10m ago
Only until a single server running nginx is hacked and the binary leaked though...
Hizonner•5m ago
Um, the nginx binary would have to be in the hands of hundreds of thousands of server operators. And the set of server operators is rich in the kind of person who would attack it. Not to mention the huge number of leaks you'd get.

Maybe if it's some server-side software that you only use yourself...

merelydev•13m ago
True. Its a trade-of, LLMs in this regard are only effective when they have access to the source code?

I do not wish to undermine the philosophical underpinnings of free software and its net benefit to society. Without it we wouldn't even have the code generators we have today.

blensor•12m ago
And isn't it also mostly a transitioning issue. Those open codebases will be constantly scanned for potential security issues and getting more and more hardened. There are probably a lot of easy wins that are going to be discovered over the next few years but it should taper out after a while.
merelydev•11m ago
Fair point but it assumes we all have access to LLMs with the same capabilities.
Tiberium•21m ago
Are they all actually 0-day? I think a lot of them are from disclosed CVEs/code that were already fixed upstream. It often seems like the term "0-day" has lost most of its meaning today and people often use it to refer to any exploits.
tempest_•6m ago
Repo claims

> A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.

Which is roughly the definition of zero day. Whether the contents of the repo reflect the above claim is something else entirely.

jdw64•20m ago
I'm going through each one, and it's fascinating to see things like this. The UAF principle in c-ares is really interesting.

The problem ultimately came from not being able to prevent stale pointers. The attack works by figuring out the size of the stale pointer, then spraying memory with data of the same size, and finally achieving RCE (Remote Code Execution). How do people even come up with ideas like this?

jdw64•6m ago
But do people actually find these vulnerabilities on their own, or are they using LLMs? I was curious about how these vulnerabilities work, so I tried asking my dear friend Mr. CLAUDE, but he immediately threw an error and ended the session because it was a cybersecurity question. Enterprise APIs block even the analysis itself, so it's amazing that people can actually pull this off in practice.
mrbluecoat•9m ago
A surprising amount of documentation if the actor was just LLM-dropping these..
tliltocatl•5m ago
A friendly reminder that a 0-day is a vulnerability that wasn't known until after a malicious actor exploited it. If someone publishes a PoC, it is not a 0-day, just a vulnerability.
Retr0id•4m ago
I took a look at the Ghidra ones (because I use Ghidra), and I'm unimpressed: https://github.com/bikini/exploitarium/blob/main/ghidra-12.1...

The first requires being able to overwrite binaries in the Swift tool directory. Yes, if you overwrite binaries executed by ghidra, you can trigger code execution. This is not a surprise.

The second, idk, I'm not familiar with TraceRMI.

The third is not a vulnerability in the slightest, they just demonstrate that native 7zip parsing code is reachable. Maybe there is a bug in the 7zip parser, but without that it's meaningless.

What Is a File Format?

https://growingswe.com/blog/file-formats
1•jawbreaker•1m ago•0 comments

Australian rescue team uses AI-powered drone to find lost hikers [video]

https://www.youtube.com/watch?v=bUjteM5NwuY
1•hackerbeat•1m ago•0 comments

Remediation Asymmetry: When Agents Can Diagnose More Than They Can Fix

https://imaxxs.com/remediation-asymmetry-agents-diagnose-more-than-fix
1•imaxxs•1m ago•0 comments

Catch silent Meta/TikTok CAPI failures before they tank your matching

https://github.com/lsb11/shopify-capi-validator
1•StackArchitect•2m ago•0 comments

Native Hacker News TUI client with AI comments summary written in Golang

https://code.intellios.ai/cwnews/
1•coolwulf•4m ago•0 comments

Org Novelist

https://github.com/sympodius/org-novelist/
1•ycombinete•6m ago•0 comments

Engine Simulator – Community Edition

https://github.com/Engine-Simulator/engine-sim-community-edition
1•andre9317•9m ago•1 comments

Show HN: Luma – A New Workspace for Frida

https://luma.frida.re/
1•oleavr•9m ago•0 comments

Legion LegalTech sues U.S. over Anthropic Fable 5 and Mythos 5 shutdown

https://thenextweb.com/news/legion-legaltech-sues-us-anthropic-access
2•airstrike•16m ago•0 comments

Non-Existent or Intermittent Internet Access When Using FusionAuth (2025)

https://fusionauth.io/community/forum/topic/3055/non-existent-or-intermittent-internet-access-whe...
1•mooreds•19m ago•0 comments

Apple seeks to buy memory chips from blacklisted Chinese company

https://www.ft.com/content/d72a25e2-7bde-4aa9-bd8d-0c4f3d6cb2cb
3•ksec•24m ago•1 comments

The PM's Guide to Managing AI Debt

https://newsletter.artofsaience.com/p/the-pms-guide-to-managing-ai-debt
2•mooreds•25m ago•0 comments

You've tried DuckDuckGo and Brave Search, now get serious with SearXNG

https://www.neowin.net/editorials/youve-tried-duckduckgo-and-brave-search-now-get-serious-with-se...
3•philonoist•27m ago•0 comments

Liquid-Cooling a TE Connectivity 800V DC Busbar and More from the Wiwynn Booth

https://www.servethehome.com/liquid-cooling-a-te-connectivity-800v-dc-busbar-and-more-from-the-wi...
1•ksec•29m ago•0 comments

Text Files as a User Interface

https://ratfactor.com/cards/text-files-as-ui
3•birdculture•31m ago•0 comments

Show HN: HotFX Pseudorandom – value noise in a CSS variable via custom element

https://fx.hot.page/pseudorandom
2•WebBurnout•31m ago•0 comments

Passkey Central

https://www.passkeycentral.org/home/
2•mooreds•32m ago•0 comments

Microsoft extends free Windows 10 security updates until October 12, 2027

https://www.tomshardware.com/software/windows/microsoft-extends-free-windows-10-security-updates-...
3•aleph_minus_one•35m ago•0 comments

Show HN: Ocarina – Automate and test MCP servers from YAML, no LLM

https://github.com/msradam/ocarina
2•msradam•35m ago•0 comments

The State has entered the Model Loop

https://peteridah.substack.com/p/the-state-has-entered-the-model-loop
2•peteridah•39m ago•1 comments

Back to the good old times – Win 7 for Debian (2024)

https://mehdy.eu/back-to-the-good-old-times-win-7-for-debian/
3•TuringTux•41m ago•0 comments

Distributed LLM Inference with LLM-d

https://cefboud.com/posts/llm-d/
3•cefboud•42m ago•0 comments

Double threat to privacy: Chat Control 1.0 and 2.0 are back

https://old.reddit.com/r/europe/comments/1ugc4td/double_threat_to_privacy_chat_control_10_and_20/
4•nickslaughter02•42m ago•0 comments

Height of Harmonic Numbers

https://www.johndcook.com/blog/2026/06/27/height-of-harmonic-numbers/
2•ibobev•42m ago•0 comments

Art by Maths

https://www.mathchronicles.org/copy-of-the-math-behind-the-rsa-encry
2•jruohonen•42m ago•0 comments

The Demoralization of the White-Collar Worker

https://nooneshappy.com/article/the-demoralization-of-the-white-collar-worker/
2•zdw•43m ago•0 comments

Show HN: Use any SVG as QR code On Dots

https://bar.codes/
2•Ciaranio•43m ago•0 comments

Four New Chameleon Species Found in Tropical "Sky Islands"

https://nautil.us/four-new-chameleon-species-found-in-tropical-sky-islands-1282292
2•Brajeshwar•47m ago•0 comments

Thousands more artists join Ireland's basic income plan

https://rgmii.org/blog/thousands-more-artists-join-irelands-basic-income-plan/
3•colinprince•47m ago•1 comments

Show HN:I got tired of spending 3hrs daily on job applications,so I automated it

https://jobspire.co.in/
3•cbyteai•47m ago•1 comments