Anonymous GitHub account mass-dropping undisclosed 0-days(github.com)
849 points by binyu 22 hours ago | 329 comments
tl;dr: An anonymous GitHub user has published a consolidated repository of ~20 proof-of-concept exploits targeting major projects including FFmpeg, libssh2, Ghidra, ImageMagick, VLC, Firefox, Docker, RustDesk, and PHP, many appearing to be undisclosed 0-days. The author claims the findings come from an AI-automated fuzzing workflow (using a GPT-5-class model) paired with hand-written PoCs, and defends their methodology by citing prior academic work on fuzzing. The drop has raised concerns over mass disclosure without coordinated vendor notification.
HN Discussion:
  • The reported findings are unimpressive bugs, not genuine 0-day vulnerabilities
  • The term '0-day' is being misused; many may be already-disclosed or fixed issues
  • AI-generated security reports tend to produce noisy, low-quality findings inflated by volume
  • ~This is a transitional phase; AI-found vulnerabilities will improve and noise will decrease over time
  • Practical question about whether GitHub identity requirements make the anonymous author traceable