
Lastenzug
Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

To reproduce CVE-2021-31630

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

CVE-2025-53652: Jenkins Git Parameter Analysis

CVE-2022-1292 OpenSSL c_rehash Vulnerability

CImg Library v.2.3.3 - command injection

Details about the Blind RCE issue(SPX-GC) in SPX-GC

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Automatic SSTI detection tool with interactive interface

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

CVE-2020–14882、CVE-2020–14883

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

a guard that blocks catastrophic agent actions