
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Curated index of high-quality resources, tools, and learning materials across software development, security, platforms, and more, maintained by the…

快速搭建各种漏洞环境(Various vulnerability environment)

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Proof of concept code for Datadog Security Labs referenced exploits.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.


Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security


The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

cve-2017-1000117

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape