<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Disclosure on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/vulnerability-disclosure/</link><description>Recent content in Vulnerability-Disclosure on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 22 Jul 2026 15:01:21 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/vulnerability-disclosure/index.xml" rel="self" type="application/rss+xml"/><item><title>Exploitarium Dropped 204 Live Exploits for curl libssh2 and Nmap With No Warning</title><link>https://hackingpassion.com/exploitarium-github-zero-day-dump/</link><pubDate>Wed, 22 Jul 2026 15:01:21 +0200</pubDate><guid>https://hackingpassion.com/exploitarium-github-zero-day-dump/</guid><description>&lt;p>Someone published &lt;strong>204 exploit files&lt;/strong> on GitHub for software you almost certainly use, and told the vendors nothing. The makers found out the same way the attackers did, by reading the page. 🧐&lt;/p>
&lt;p>The account goes by &lt;strong>bikini&lt;/strong>. The project is called &lt;code>exploitarium&lt;/code>, a single archive of ready-to-run exploit code for software that sits underneath much of what you use. The first dated entries go back to &lt;strong>June 23&lt;/strong>, and by &lt;strong>June 27&lt;/strong> the page was pulling in stars and hundreds of comments, which meant defenders and attackers were reading the same exploits at the same moment.&lt;/p></description></item><item><title>Six Working Windows Zero Days and the Researcher Microsoft Called a Criminal</title><link>https://hackingpassion.com/nightmare-eclipse-microsoft-zero-day-war/</link><pubDate>Sun, 31 May 2026 15:08:03 +0200</pubDate><guid>https://hackingpassion.com/nightmare-eclipse-microsoft-zero-day-war/</guid><description>&lt;p>Six working Windows attacks are sitting in the open right now, three of them already seen in a real intrusion, and the researcher who published them did it after he says Microsoft refused him, deleted the account he reported bugs through, and paid him nothing. Microsoft removed his account, called his actions criminal, and pointed at its crime unit. Both stories are out there, and the security world cannot agree on who is more to blame.&lt;/p></description></item></channel></rss>