
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

EU focused compliance MCP server

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Identify privilege escalation paths within and across different clouds

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

Unified dashboard to monitor, govern, and audit AI agents in real-time. Enforce budgets, detect policy violations, and export compliance reports for…

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

CVE-2024-10220 reveals a critical flaw in Kubernetes’ deprecated gitRepo volume type, allowing attackers to execute arbitrary commands via malicious…

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

ClusterImagePolicy demo for cve-2022-42889 text4shell

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

Summary of Cyber Security interview questions I have been through, hope this helps