
DevSecOpsGuideline
The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…


Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.


CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

cve-2017-1000117

快速搭建各种漏洞环境(Various vulnerability environment)

Curated index of high-quality resources, tools, and learning materials across software development, security, platforms, and more, maintained by the…

Proof of concept code for Datadog Security Labs referenced exploits.

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…