A self-styled group calling itself 0day Rubbish has publicly released a new batch of enterprise software zero-days on GitHub without coordinated disclosure, publishing working proof-of-concept exploits for vulnerabilities it says can lead to root or SYSTEM remote code execution. The latest batch reportedly includes eight advisories affecting HiveMQ Platform, GigaSpaces XAP, IceWarp Server, KeyHelp, Loadbalancer.org ADC, Biamp Vocia MS-1, Voicent Call Center, and Joget Workflow Enterprise, with most described as critical; the group says five issues are unauthenticated and three require authenticated exploit chains.
The GitHub project presents the campaign as an AI-driven vulnerability production pipeline, claiming it uses multiple LLMs for discovery, followed by fuzzing, code review, manual validation, and exploit development before direct public release. According to the published material, the group has disclosed 51 vulnerabilities across five batches and frames the effort as pressure on vendors to improve security, while warning that future disclosures could expand into ICS/SCADA, energy, and aerospace targets.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
0day Rubbish publicly disclosed an authenticated remote code execution and privilege escalation flaw in ONE Reporter 13.1 via the Full Disclosure mailing list. The advisory said a low-privilege authenticated user could exploit CommandExecutor command injection to execute arbitrary commands as a local-admin service account; the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed an unauthenticated remote code execution flaw in JetBrains Datalore On-Premises 2026.2.3 via the Full Disclosure mailing list. The advisory described an InteractiveReport access-mapping flaw allowing anonymous attackers to execute arbitrary code in the notebook agent container, and said the vendor had been notified while a CVE remained pending.
0day Rubbish publicly disclosed a critical vulnerability in RoboTask 11.0.5.1229 via the Full Disclosure mailing list. The advisory said unauthenticated attackers could enumerate and trigger pre-existing tasks through the REST API with Administrator privileges; the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed an authenticated command injection vulnerability in VMS 6.48.809 via the Full Disclosure mailing list. The advisory said a low-privileged authenticated attacker could execute arbitrary commands as root over the network without user interaction, and noted the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed an unauthenticated arbitrary file write vulnerability in Tornado 2.11.3 via the Full Disclosure mailing list. The advisory said attackers could abuse storeTo=file: to write to cron and achieve root remote code execution; the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed an unauthenticated remote code execution flaw in ActiveFax Server 10.70 via the Full Disclosure mailing list. The advisory said attackers could send a malicious LPD print job exploiting Ghostscript %pipe% command injection to execute arbitrary commands as SYSTEM; the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed an authenticated remote code execution flaw in Plixer Scrutinizer 19.7.0 via the Full Disclosure mailing list. The advisory said a SQL injection in the adminEditLang handler could be abused by an authenticated administrator to use pg_cron and a PostgreSQL SUPERUSER role to execute arbitrary commands as the postgres user; the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed a pre-authentication remote code execution flaw in Srimax Software's Output Messenger Server 2.0.x (from 2.0.63) via the Full Disclosure mailing list. The advisory said unauthenticated attackers could exploit improper XMPP authentication and a Zip-Slip plugin planting issue to achieve LocalSystem code execution after service restart; the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed a pre-authentication remote code execution flaw in MidVision RapidDeploy 5.2.2 via the Full Disclosure mailing list. The advisory said a default remote-agent template exposed JBoss Remoting without authentication, enabling arbitrary file writes that could be leveraged for root-level code execution; the vendor had been notified and a CVE was still pending.
0day Rubbish publicly disclosed a pre-authentication remote code execution flaw in Workflow Enterprise 9.1.0.1 via the Full Disclosure mailing list. The advisory described an expression injection issue enabling unauthenticated root-level code execution, said the vendor had been notified, and noted that a CVE was still pending.
0day Rubbish publicly disclosed a pre-authentication remote code execution flaw in Call Center Suite 10.10.1 via the Full Disclosure mailing list. The advisory described an authentication bypass plus webroot write issue enabling unauthenticated root-level code execution, said the vendor had been notified, and noted that a CVE was still pending.
A GitHub repository under the name "0day Rubbish" was published presenting the group's manifesto and approach of publicly disclosing enterprise software zero-days without vendor coordination.
In describing its activities, the group claimed a cumulative total of 51 vulnerabilities disclosed across five batches. The same material says the vulnerabilities were produced through an automated multi-LLM discovery pipeline followed by fuzzing, code review, manual validation, and exploit development.
The group publicly disclosed a fifth batch of eight advisories affecting HiveMQ Platform, GigaSpaces XAP, IceWarp Server, KeyHelp, Loadbalancer.org ADC, Biamp Vocia MS-1, Voicent Call Center, and Joget Workflow Enterprise. The post says the batch includes five unauthenticated issues and three authenticated deep-chain issues, all with reproducible proof-of-concept exploits leading to root or SYSTEM compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcecyberveille.ch
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.