
cve-2026-13934
Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

Linux 内核升级指南 - 修复 CVE-2026-64561

My cheatsheet notes to pentest AWS infrastructure

Lord Of Active Directory - automatic vulnerable active directory on AWS

A collection of web browser CTF challenges and solutions.

how to look for Leaked Credentials !

Slides and Codes used for the workshop Red Team Infrastructure Automation


Proof-of-concept exploit for CVE-2026-9999, demonstrating path traversal in serverless object storage events that overwrites function source code to…

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…

Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

Create your own vulnerable by design AWS penetration testing playground

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

Technical PoC for CVE-2026-2472 (GCP-2026-011): Unauthenticated and Stored Cross-Site Scripting (XSS) in google-cloud-aiplatform…

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms…