
gpgsm-cve-2026-57062-cms-gcm-short-tag
Proof-of-concept demonstrating a CMS AES-GCM short-tag authentication bypass in GnuPG's gpgsm (CVE-2026-57062). Forges a message that decrypts on…

Proof-of-concept demonstrating a CMS AES-GCM short-tag authentication bypass in GnuPG's gpgsm (CVE-2026-57062). Forges a message that decrypts on…

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

Reference implementation of a multi-bit LLM watermarking scheme using coded payload spreading, unbiased reweighting, and soft-decision ECC decoding…

Curated repository of Qubes OS security bulletins, canaries, PGP keys, and ISO digests, with authenticated verification via git tags and detached…

A cryptographic research tool for analyzing signature vulnerabilities

C library implementing FrodoKEM, a post-quantum key encapsulation mechanism based on the Learning with Errors problem, with variants for AES and…

Obfuscates Java source code to protect against reverse engineering, decompilation, and IP theft. Renames variables/methods, encrypts strings, and…

LoRaWAN session cracker - A PoC for exploiting weak or shared Application Keys

Web-based GUI for Hashcat that simplifies password cracking with session management, mask generation, wordlist support, and multi-user access.

Perform ECDSA and DSA nonce reuse private key recovery attacks to analyze signature vulnerabilities and recover private keys from blockchain…

C library for prototyping and experimenting with quantum-resistant cryptography

Post-quantum cryptographic scheme implementation (Hamming Quasi-Cyclic) with reference and optimized versions for secure key encapsulation.

Steganographic online codec allows you to hide a password encrypted message within the images & photos using AES encryption algorithm with a 256-bit…

Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)