
aisecplus-week01-servicenow-ai-security-incident
Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

A technical case study and timeline dataset documenting Google Gemini 2.5 Pro's safety alignment policies, guardrails, and refusal behavior evolution…

Ensemble framework for software vulnerability detection and repair using multiple large language models, with consensus analysis and evaluation tools…

Technical analysis of the LangChain serialization injection vulnerability CVE-2025-68664.

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in…

vulnerability in CVE 2025-9998 and solution for those vulnerability with help artificial intelligence

VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection

Study of CVE-2018-6341 in React, demonstrating AI-assisted vulnerability detection, root-cause analysis, and remediation guidance for JavaScript…

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

PoC for CVE-2025-62593: unauthenticated RCE in Ray (CISA KEV). Stdlib-only Python.

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize


Automating Host Exploitation with AI

AI Smart Contract Security Analysis and PoC Generation Framework

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…