
CVE-2021-44228
Apache Log4j is a logging tool written in Java. This paper focuses on what is Log4j and log4shell vulnerability and how it works, how it affects the…

Apache Log4j is a logging tool written in Java. This paper focuses on what is Log4j and log4shell vulnerability and how it works, how it affects the…

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

This is a repo which documents real bugs in real software to illustrate trends, learn how to prevent or find them more quickly.

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Tips on how to write exploit scripts (faster!)

This OSINT Notebook provides an overview of the tools, techniques, and resources that I use for a variety of situations when it comes to performing…

A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way that specific…

How Enable Security handles security vulnerabilities

How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX

I Found a Zero-Day Vulnerability in OpenClaw — Here’s How It Went

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

A curated list of awesome OSCP resources

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.