
aws-log4j-mitigations
CVE-2021-44228 log4j mitigation using aws wafv2 with ansible

CVE-2021-44228 log4j mitigation using aws wafv2 with ansible

Production-grade tool for detecting & remediating CVE-2026-0622 (Ghost Admin privilege escalation & master key exposure in 5G core software).

Mitigates CVE-2016-5195 aka DirtyCOW

CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898

Open-source, cross-platform, multi-purpose security auditing tool

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

a Damn Vulnerable Serverless Application

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Hands-on lab demonstrating Kubernetes container hardening by comparing default vs. security-enhanced deployments of a vulnerable note-taking…

An at-rest encrypted filesharing application with multiple clients who seek to share privately, without tracking.

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

Jakarta EE and MicroProfile application server runtime for development and containerized deployments, supporting cloud-native middleware with…