bikini is an anonymous security researcher persona associated with the uncoordinated public release of working zero-day exploit code affecting multiple software products and open-source projects. The activity is notable for publishing exploit material without prior vendor or maintainer notification, increasing immediate defensive pressure on exposed organizations. Reported disclosures included high-risk vulnerabilities such as a pre-authentication remote code execution flaw in libssh2 and an authentication bypass affecting self-hosted Docker deployments of Gitea, both described as under active exploitation at the time. The activity aligns with exploitation of public-facing applications and related vulnerability research and weaponization workflows. Reported capabilities evidenced by the disclosures include initial access through exploitation, privilege-escalation-related exploit publication, and credential- or identity-compromise-related exploit publication via authentication bypass. The persona has also been discussed in connection with potentially automated fuzzing and vulnerability discovery, although automation details are not established at high confidence. Available information supports characterization of bikini as an anonymous exploit publisher or researcher persona rather than a clearly established intrusion set, ransomware operation, or nation-state threat actor. Attribution to any country, operational cluster, or enduring sub-group is not currently available at high confidence. The label "Nightmare Eclipse" appears in the broader reporting context, but a confirmed alias or organizational relationship is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2026-20896 : Contournement d’authentification critique dans Gitea (déploiements Docker auto-hébergés), permettant à un attaquant non authentifié d’usurper l’identité de n’importe quel utilisateur et de prendre le contrôle total du serveur Git. Corrigé dans Gitea 1.26.3.
CVE-2026-55200 : RCE pré-authentification critique dans libssh2 (bibliothèque C client SSH2). Des attaquants distants peuvent envoyer des paquets SSH avec des valeurs packet_length excessivement grandes pour corrompre la mémoire heap et exécuter du code arbitraire. Un correctif a été fusionné dans la branche principale mais aucune release officielle n’est encore disponible.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.