
nah
a guard that blocks catastrophic agent actions

a guard that blocks catastrophic agent actions

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Automatic SSTI detection tool with interactive interface

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

To reproduce CVE-2021-31630

CVE-2025-53652: Jenkins Git Parameter Analysis

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

CImg Library v.2.3.3 - command injection

Details about the Blind RCE issue(SPX-GC) in SPX-GC

My experiments in weaponizing Nim (https://nim-lang.org/)

.NET/PowerShell/VBA Offensive Security Obfuscator

Rust Weaponization for Red Team Engagements.