
gha-lab-e8902eccd3
Security research lab: reproduction of CVE-2025-52467 (pgai pull_request_target workflow code execution / GITHUB_TOKEN exfiltration) — snapshot of…

Security research lab: reproduction of CVE-2025-52467 (pgai pull_request_target workflow code execution / GITHUB_TOKEN exfiltration) — snapshot of…

Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.

Curated OSINT compilation on Log4Shell (CVE-2021-44228) covering detection methods, attack surface, mitigation steps, and indicators of compromise…

Technical analysis and educational resource for CVE-2026-41940, covering root cause, scanner behavior, prevention, mitigation, IOC hunting, and VaPT…

I Found a Zero-Day Vulnerability in OpenClaw — Here’s How It Went

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

Summary of Cyber Security interview questions I have been through, hope this helps

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

This OSINT Notebook provides an overview of the tools, techniques, and resources that I use for a variety of situations when it comes to performing…

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Tips on how to write exploit scripts (faster!)

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way that specific…

How Enable Security handles security vulnerabilities

This is a repo which documents real bugs in real software to illustrate trends, learn how to prevent or find them more quickly.

Clickbait. The CVE is AI slop.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A curated list of awesome OSCP resources