Clandestine[verified]@akaclandestinePoC
The post references CVE-2024-21626 and links to bug‑bounty notes that likely contain a proof of concept, but it does not highlight any exploit code, patch, or evidence of active exploitation.
felipehuici[verified]@felipehuiciActive Exploitation
The post highlights that multiple runc and kernel CVEs are actively exploited in the wild, underscoring persistent container escape threats.
shubham kumar[verified]@kumar98_shubhamPoC
The post presents a proof of concept demonstrating a privileged escape in runc via an unclosed file descriptor and highlights additional mount race vulnerabilities in 2025, but does not provide exploit code, patches, or evidence of active exploitation.
Jérôme Jaggi[verified]@JeromeJaggiActive Exploitation
The post highlights several container-related CVEs, noting that at least one (CVE-2025-52881) has been exploited in the wild, underscoring ongoing security concerns with container platforms.
DFIR Lab[verified]@DFIR_LabPatch
The tweet announces CVE-2024-21626, a high-severity container escape flaw in runc, and urges users to update to version 1.1.12 immediately.
Milos Constantin ♏(@Tinolle hachyderm.io )@TinollePoC
A link to a note on CVE-2024-21626 implies that a proof‑of‑concept for this runc container breakout exists and technical details are provided, but there is no evidence of active exploitation, patches, or debunking.
strikoder@StrikoderExploit
The post outlines a HackTheBox walkthrough that demonstrates a multi-stage exploitation chain ending with a container escape via CVE-2024-21626, but it does not provide code or evidence of active attacks.