
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

ClusterImagePolicy demo for cve-2022-42889 text4shell

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

Summary of Cyber Security interview questions I have been through, hope this helps

CVE-2024-10220 reveals a critical flaw in Kubernetes’ deprecated gitRepo volume type, allowing attackers to execute arbitrary commands via malicious…

EU focused compliance MCP server

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

Identify privilege escalation paths within and across different clouds

Unified dashboard to monitor, govern, and audit AI agents in real-time. Enforce budgets, detect policy violations, and export compliance reports for…

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability