
awesome-ai-security
A collection of awesome resources related AI security

A collection of awesome resources related AI security

Adversary Emulation Framework

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Detects LLM context-leakage attacks by training lightweight behavior probes on log-probabilities, with vLLM offline/server detection pipelines.

Proof-of-concept exploit for CVE-2026-73292: CSRF attack on Semaphore UI password change endpoint, serving a malicious page that silently resets an…

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Local white-box gradient attacks for open-weight LLMs: GCG/PEZ suffix search, layer saliency, weight snapshots, and rank-1 suffix-to-delta fitting…

CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

Open-source adversary emulation for AI agents and MCP servers.

Simple (relatively) things allowing you to dig a bit deeper than usual.

CVE-2026-20685 - Draft or TODO

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Proof-of-concept exploiting WordPress pre-auth XSS to RCE via DOM clobbering, REST API abuse, and malicious plugin upload for server-side execution.…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go
