


💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Structured security knowledge base with production-inspired cases: vulnerability analysis, exploit explanation, remediation, and DevSecOps for…

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…


VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

cve-2017-1000117