An anonymous researcher publishing as bikini released exploit code for zero-day vulnerabilities across 15 projects in a now-removed GitHub repository called exploitarium without prior vendor notification. At least two critical issues, a pre-auth RCE in libssh2 and an authentication bypass in Gitea Docker setups, are under active attack according to analysts who also linked the work to AI-assisted fuzzing.

Feel free to report them yourself and take credit for the CVE if handed out lulz
Please do not abuse these. I do this so to allure people into the field.
Security teams should prioritize patching libssh2 and Gitea instances immediately while deploying the newly released KQL and YARA detection rules, as AI-driven exploit publication is compressing the window between discovery and weaponization.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Google released Gemini 3.7 Flash with enhanced capabilities in coding, web development, document analysis and automated agent execution while cutting token prices by 50% through the end of the year. The model is now live in 160 countries and powers the Gemini Spark agent exclusively for AI Pro and Ultra subscribers.
Apple has placed the iPhone X and the 2018 15-inch MacBook Pro on its obsolete products list, ending eligibility for hardware repairs at Apple and authorized providers. The move follows the company's seven-year policy after it stopped distributing the devices, with iOS 16 having been the last major iOS version for the iPhone X.
IBM Db2 versions 11.5.0–11.5.9 and 12.1.0–12.1.5 allow privilege escalation through a specially crafted query. CVE-2026-10543 carries a CVSS 3.1 score of 8.2 high, stems from improper authorization (CWE-285), and was published August 12, 2026. An IBM advisory is available.