
ironclaw
Secure, private AI agent operating system with local encrypted storage, OAuth/SSO authentication, policy-based access control, and extensible…

Secure, private AI agent operating system with local encrypted storage, OAuth/SSO authentication, policy-based access control, and extensible…

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

An open-source framework for verifiably private AI inference

The most comprehensive authentication framework

The Symfony PHP framework

A framework for creating smart cards (ICC-based cards with contacts).

Core framework for identity and access management, providing authentication, authorization, and identity governance capabilities for enterprise…

Python-based framework for generating Golden SAML tokens, Kerberos tickets, and Azure Access Tokens to exploit federated identity systems and…

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

A flexible, composable authorization framework for Kit (inspired by Action Policy)

cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets

Proof-of-concept demonstrating authorization bypass in Spring Security's RegexRequestMatcher (CVE-2022-22978) using CRLF injection, with analysis and…

Open-source services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, JAX-WS, and JAX-RS APIs.

POC of CVE-2022-36537

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.