
CVE-2026-52885
Technical analysis of CVE-2026-52885: a TOCTOU race condition in Notepad++ v8.9.6.2 allowing arbitrary command execution via HMAC integrity bypass.…

Technical analysis of CVE-2026-52885: a TOCTOU race condition in Notepad++ v8.9.6.2 allowing arbitrary command execution via HMAC integrity bypass.…

LLVM-based security research toolchain: NeverC, a C23 cross-compiler, and NeverD, a binary analysis and decompilation engine that lifts PE, ELF,…

C++ reimplementation of Ghidra's analytical core without JVM dependencies, providing embeddable binary analysis, Pcode/Sleigh foundations, and…

Python library for local LLM-powered security analysis with Ghidra binary analysis, C/C++ vulnerability scanning, and MCP tool integration for…

Technical analysis of CVE-2025-66628, an integer overflow in ImageMagick's TIM parser leading to out-of-bounds reads, with root cause, exploitation…

Security research project on fuzzing libpng with OSS-Fuzz. Includes seed corpus analysis, custom read/write fuzzers, and a proof-of-concept exploit…

C library for stream-oriented XML parsing with a focus on vulnerability analysis and exploitation of CVE-2022-43680, enabling fuzzing and…

Proof-of-concept exploit for CVE-2013-3900, a WinVerifyTrust signature validation vulnerability enabling arbitrary code execution via crafted…

Analyzes and patches a specific Android vulnerability (CVE-2023-21282) in the AAC audio codec, providing a patched AOSP10 source tree for security…

C library for VP8/VP9 video encoding and decoding, with a focus on security patching for CVE-2023-5217.

In-depth technical analysis of CVE-2021-25804, a VLC AVI parser vulnerability. Includes root cause, patch diff, and exploitation primitives for…

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).

Anti-LLM obfuscation via finger counting

Pishi is a code coverage tool like kcov for macOS.

Zyrox: LLVM based, compile-time obfuscator plugin.