0xdf@0xdf_Disclosure
The blog post announces discovery and demonstration of three CVEs (Cacti RCE and Docker Desktop API abuse) via PHP type juggling, but does not provide exploits, patches, or evidence of active exploitation.
Red Secure Tech Ltd.@redsecuretechDisclosure
The tweet announces that CVE‑2025‑9074 in Docker Desktop <4.44.3 permits unauthenticated API access from malicious containers, potentially leading to host file access and escape.
Tao Idr@tao_idrDisclosure
The post discloses CVE-2025-9074 in Docker Desktop, describing its high‑severity (CVSS 9.3) flaw that lets containers reach the Docker Engine API without authentication and escape to the host, but it does not mention any PoC, exploit code, active attacks, or remediation.
sckull@sckull_PoC
A post on HackTheBox outlines the discovery of CVE-2025-9074, noting that API credentials can be exposed, enabling password spraying and remote code execution, and provides a link to the author’s detailed write‑up.
Tao Idr@tao_idrGeneral
The post lists a high‑severity vulnerability (CVE‑2025‑9074, CVSS 9.3) and research sources, but provides no evidence of PoC, exploit tools, active exploitation, or patch information.
Waqar Naeem@codewithpikePoC
The post notes that the author leveraged publicly available PoCs to exploit a Cacti reverse shell and Docker host escape CVEs as part of an easier Hack The Box box, focusing on how to use these PoCs rather than providing new exploit code or reporting live attacks.
Byron Warner@ScanSafeGuardPatch
CVE-2025-9074 lets unauthenticated containers access the Docker Engine API and escape to the host; a PoC exists and a patch (Desktop 4.44.3) is available for affected versions.