othervia Hacker News · 861 points · 334 comments

Real bugs, real PoCs, and a disclosure strategy that looks like “YOLO CVE farming.”

bikini/exploitarium undisclosed 0-day dump

// sus score

68/100
HIGH SUS

This looks less like responsible disclosure and more like raw vulnerability clout with a README attached.

// the decode

Unlike a lot of security theater, this repo appears to contain real, specific technical work: named targets, PoCs, commit history, and even integrity checks for migrated repos. The sus part is the disclosure model and the incentives: the author says issues were publicly posted before being reported, invites others to grab CVE credit, and uses a flimsy "do not abuse" disclaimer after publishing weaponizable details. So this is not empty hype, but it is a very real example of substance wrapped in attention-seeking and incentive-misaligned behavior.

// the case for

  • +The repository includes concrete targets, PoC folders, dates, and commit history rather than vague claims
  • +The consolidation/integrity section is unusually specific and technically verifiable
  • +The author does acknowledge uneven quality and credits at least one prior finder
  • +There appears to be real hands-on vulnerability research here, not just AI-generated security cosplay

// the case against

  • Publicly dropping apparently unreported vulnerabilities shifts risk onto users before vendors can patch
  • Inviting others to take CVE credit creates perverse incentives and turns disclosure into a race
  • The disclaimer against abuse is performative once exploit details are already public
  • Anonymous publication makes accountability and follow-up harder
  • Claims about methodology and expertise are only partially substantiated in the provided text

// red flags

  • !"At the time I post these, none have been reported"
  • !"Feel free to report them yourself and take credit for the CVE"
  • !"Please do not abuse these" after publishing exploit PoCs
  • !"one new PoC a day" framing that treats disclosure like content cadence
  • !Anonymous/handle-based identity with Discord contact but no visible responsible disclosure policy
  • !No evidence in the text of vendor notification, patch status, or coordination timelines
  • !Motivation framed partly as audience growth: "Sharing this repo keeps me motivated to continue dropping my findings"
  • !Claims of research quality are partly self-attested (degree, papers, methodology) without links in the provided text

// buzzwords detected

AIGPT-5.5-3-Codex-SparkSOTA modelvibe-coded

// follow the incentives

The account gains reputation, followers, stars, and status in security circles by being the person who drops fresh bugs first. Anyone who rushes to file the issue may get CVE credit, while defenders and vendors absorb the cleanup cost. The likely real motive is a mix of genuine research publication, community attention, and anti-gatekeeping posture—not exactly profit-maximizing, but definitely incentive-maximizing.

// what they're not telling you

What's missing is the part that matters most: which vendors were notified, whether fixes exist, whether exploitation requires unusual conditions, how severe each issue actually is, and whether any of these were already known privately. There is also no consistent severity rubric, no coordinated disclosure timeline, no reproduction environment details at the repo top level, and no evidence that the "don't abuse this" warning is backed by any meaningful safeguards.

// sponsored

// published by

Sus in Binary

Independent tech-analysis. AI-assisted, editorially reviewed.

// AI-generated skeptical analysis of a publicly reported claim. Opinion, not financial advice. Source linked above; original text not reproduced.