
CVE-2026-Discord
Critical vulnerability report detailing zero-day Remote Debugging Port exposure in Discord macOS client leading to account takeover, spyware, worm…

Critical vulnerability report detailing zero-day Remote Debugging Port exposure in Discord macOS client leading to account takeover, spyware, worm…


Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

CitrixBleed2 poc

Exploit script for CVE-2025-24071 that leaks NTLM hashes from Windows by extracting a crafted ZIP/RAR file, exploiting .library-ms file handling.…

Citrix Bleed 2 PoC Scanner (CVE-2025-5777)

Step-by-step penetration testing lab exploiting Samba CVE-2007-2447 on Metasploitable 2 using Metasploit, demonstrating root compromise, credential…

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Proof-of-concept exploit for authenticated arbitrary file read via directory traversal in WordPress Tainacan plugin (CVE-2024-7135).

Proof-of-concept exploit for CVE-2024-56428 that reads cleartext credentials from iLabClient's local Apache Derby database.

Bash PoC script exploiting CVE-2019-6447 in ES File Explorer to list files, photos, videos, apps, and download files from vulnerable Android devices.

A simple remote tool in C#.

👁️ (s)AINT is a Spyware Generator for Windows systems written in Java. [Discontinued]

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

Search (offline) if your password (NTLM or SHA1 format) has been leaked (HIBP passwords list v8)

Tool to search secrets in various filetypes.

:key: (THIS CODE IS OUTDATED FOR NEW CHROME VERSIONS) Decrypt chromium based browsers passwords, cookies, credit cards, history, bookmarks, autofill.…

a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc