
CVE-2026-31431-detection-defense
Research and detection guidance for CVE-2026-31431, an io_uring-based bypass of syscall monitoring. Provides detection rules for Tetragon, Falco, and…

Research and detection guidance for CVE-2026-31431, an io_uring-based bypass of syscall monitoring. Provides detection rules for Tetragon, Falco, and…

Docker lab to compare vulnerable and patched builds of MCPJam Inspector for CVE-2026-23744, demonstrating network binding differences and API…

OS Command Injection in KubeAI via Model URL in Ollama startup probe — CVSS 8.7

Local Docker lab for comparing vulnerable and patched versions of WPvivid Backup & Migration (CVE-2026-1357) for educational verification and…

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

Proof-of-concept exploit for CVE-2026-24514, a memory exhaustion denial-of-service in ingress-nginx validating admission webhook, allowing…

BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide

Proof-of-concept for CVE-2026-29955, a command injection vulnerability in KubePlus kubeconfiggenerator allowing remote code execution and…

Docker-based proof-of-concept demonstrating CVE-2025-23320 in NVIDIA Triton inference server, exploiting shared memory key leakage to trigger an…

This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is going on right now. Why…

Terraform and Docker resources for quickly spinning up a test of CVE-2021-44428

PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.

Kubernetes driver extension of the Chaos Toolkit probes and actions API

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Secure and fast microVMs for serverless computing.

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud