
OffensiveNim
My experiments in weaponizing Nim (https://nim-lang.org/)
binary-exploitationcode-analysiscommand-and-control+8
3.1k

My experiments in weaponizing Nim (https://nim-lang.org/)

a guard that blocks catastrophic agent actions

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level