Exploitarium is a public GitHub-based archive used to aggregate and publish proof-of-concept vulnerability research across a broad range of software projects without prior vendor notification. It functions less like a conventional intrusion set and more like a lightly moderated multi-contributor clearinghouse for uncoordinated vulnerability disclosure and exploit material distribution. Activity associated with the archive expanded in mid-2026 and included submissions spanning open-source infrastructure, web applications, authentication logic, native memory-safety flaws, and kernel or driver components. The archive has been associated with an account operating under the name “bikini,” and it has incorporated material from multiple outside contributors. Reported content included vulnerabilities affecting projects such as PostgreSQL, Redis, Nextcloud, Discourse, OpenVPN-related Windows driver components, and libssh2. One of the most significant disclosures tied to the archive was CVE-2026-55200 in libssh2, a pre-authentication out-of-bounds write caused by insufficient upper-bound validation during SSH packet processing. Because libssh2 is embedded in widely used software and development tooling, the archive’s publication model creates downstream supply-chain exposure risk beyond the immediately affected project. Exploitarium’s operational significance lies in mass public release of unvetted proof-of-concept material at scale, including research that may precede patch availability. Its behavior aligns with vulnerability research publication and broad dissemination rather than financially motivated extortion or traditional espionage operations. High-confidence reporting supports reconnaissance against software attack surfaces and public release of exploit-enabling technical material, but does not support attribution to a nation-state or to a geographically defined threat cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.