#proof-of-concept
9 stories taggedproof-of-concept.

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox
A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

GitLab Flaw Lets Any Logged-In User Run Commands on Self-Hosted Servers
A researcher published working exploit code against GitLab 18.11.3 that hijacks the server through two booby-trapped notebooks and a diff request.

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch
A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw
A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. That raises the urgency for every organisation running Linux servers to patch now.

CitrixBleed Redux: PoC Drop Triggers Immediate NetScaler Memory-Scrape Campaign
Attackers wasted no time after proof-of-concept code surfaced for a new Citrix NetScaler memory-disclosure bug — the gap between publish and exploit measured in hours, not days.

RoguePlanet PoC Drops: Another Defender Race Condition, Another Path to SYSTEM
An anonymous researcher publishing as Chaotic Eclipse dropped a proof-of-concept against Microsoft Defender that wins SYSTEM on fully patched Windows — when the race goes their way.

Microsoft Threatened a Bug Hunter With Legal Action. Now It's Walking That Back.
A researcher dropped unpatched zero-days with working exploits. Microsoft's first response was to reach for the lawyers. That went poorly.

PoC Drops for 19-Year-Old Linux Kernel Privilege-Escalation Bug in CIFSwitch
A flaw that's been sitting in the kernel since the mid-2000s now has working exploit code. Low-privileged users can reach root.

Exploit Code Goes Public for Critical Flowise One-Click RCE Flaw
A published proof-of-concept puts every self-hosted Flowise deployment at risk of full remote code execution — no authentication required from the attacker, just a malicious chatflow import.