
alter-zero
RAM efficient terminal agent harness for coding, cybersecurity, and automation.

RAM efficient terminal agent harness for coding, cybersecurity, and automation.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

To reproduce CVE-2021-31630

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

CVE-2025-53652: Jenkins Git Parameter Analysis

CVE-2022-1292 OpenSSL c_rehash Vulnerability

CImg Library v.2.3.3 - command injection

Details about the Blind RCE issue(SPX-GC) in SPX-GC

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Automatic SSTI detection tool with interactive interface

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Weblogic CVE-2020-14882 unauthorized RCE exploit with patch bypass, command execution, and webshell deployment for penetration testing.

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…