<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>In-the-Wild — PoC Archive</title><link>https://poc.intelseclab.com/tags/in-the-wild/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 01 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/in-the-wild/index.xml" rel="self" type="application/rss+xml"/><item><title>WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-01_cve-2025-8088-winrar-ads-path-traversal/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-01_cve-2025-8088-winrar-ads-path-traversal/</guid><description>High severity (CVSS 8.4) — misc · CVE-2025-8088. Status: Weaponized. Affects: WinRAR (Windows). Tags: path-traversal, WinRAR, NTFS, Alternate-Data-Streams, RomCom, Storm-0978, persistence, startup-folder, in-the-wild.</description><category>misc</category><category>High</category><category>path-traversal</category><category>WinRAR</category><category>NTFS</category><category>Alternate-Data-Streams</category><category>RomCom</category><category>Storm-0978</category><category>persistence</category><category>startup-folder</category><category>in-the-wild</category></item><item><title>DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-43503. Status: Weaponized. Affects: Linux kernel (netfilter TEE / __pskb_copy_fclone()). Tags: LPE, Linux kernel, netfilter, TEE, IPsec, XFRM, page-cache, file-backed memory, DirtyFrag, skb, privilege escalation, C, in-the-wild.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>netfilter</category><category>TEE</category><category>IPsec</category><category>XFRM</category><category>page-cache</category><category>file-backed memory</category><category>DirtyFrag</category><category>skb</category><category>privilege escalation</category><category>C</category><category>in-the-wild</category></item><item><title>Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-ntlm-hash-disclosure-cve-2025-24054/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-ntlm-hash-disclosure-cve-2025-24054/</guid><description>Medium severity (CVSS 6.5) — binary · CVE-2025-24054. Status: Patched. Affects: Windows File Explorer (Windows Shell). Tags: NTLM, NTLMv2, hash-disclosure, zero-click, Windows, File-Explorer, UNC, SMB, credential-theft, in-the-wild, state-sponsored.</description><category>binary</category><category>Medium</category><category>NTLM</category><category>NTLMv2</category><category>hash-disclosure</category><category>zero-click</category><category>Windows</category><category>File-Explorer</category><category>UNC</category><category>SMB</category><category>credential-theft</category><category>in-the-wild</category><category>state-sponsored</category></item><item><title>Windows MMC MSC EvilTwin - CVE-2025-26633</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-mmc-eviltwin-cve-2025-26633/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-mmc-eviltwin-cve-2025-26633/</guid><description>High severity — binary · CVE-2025-26633. Status: Patched. Affects: Microsoft Management Console (MMC), Windows. Tags: RCE, Windows, MMC, MSC, ActiveX, EvilTwin, APT, EncryptHub, Water-Gamayun, zero-day, in-the-wild.</description><category>binary</category><category>High</category><category>RCE</category><category>Windows</category><category>MMC</category><category>MSC</category><category>ActiveX</category><category>EvilTwin</category><category>APT</category><category>EncryptHub</category><category>Water-Gamayun</category><category>zero-day</category><category>in-the-wild</category></item><item><title>Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-32433. Status: Patched. Affects: Erlang/OTP SSH server daemon. Tags: RCE, pre-auth, unauthenticated, SSH, Erlang, OTP, RabbitMQ, CouchDB, ICS, OT, reverse-shell, in-the-wild.</description><category>network</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>SSH</category><category>Erlang</category><category>OTP</category><category>RabbitMQ</category><category>CouchDB</category><category>ICS</category><category>OT</category><category>reverse-shell</category><category>in-the-wild</category></item></channel></rss>