
BrowserBox
💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Proof-of-concept demonstrating an authorization bypass in Traefik's Kubernetes Gateway provider (CVE-2026-54761) via a crossProviderNamespaces…



Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

This is an incident response playbook we created for the Vercel April 2026 compromise

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…


MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

DejaVU - Open Source Deception Framework

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.


PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Event-driven AWS security misconfiguration detection framework that monitors multiple accounts in real-time, triggering alerts via Lambda for IAM,…

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search