
openvpn
Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…
Tools for managing user identities, authentication, authorization, and access controls within systems and networks.

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

Powerful protection for AI agents - Open-source security and cost tracking for AI applications


Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Offline-first password manager with direct device-to-device sync

Local-first encrypted password manager for logins, notes, and API keys, using a SQLite vault sealed with Argon2id and XChaCha20-Poly1305; no cloud or…

Grid: Private Location Sharing mobile app for iOS/Android. E2EE with Matrix.

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Code signing and transparency for containers and binaries

Open source Dropbox-like file sharing with full client encryption !

Oracle OID LDAP Server Privileges Management Exploit

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

ksmbd CVEs: CVE-2026-31717, CVE-2026-68083

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…