
ShadeBIOS
PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

Environment with vulnerable kernel for exploitation of the TEE driver (CVE-2021-44733)

Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and…

A dependency-free C++ PLAYER for Yamaha SMAF (.mmf) ringtones: the polyphonic-ringtone format of the 2000s MA-3 / MA-5 phone chips, rebuilt with its…

Security issue in the hypervisor firmware of some older Qualcomm chipsets

Documentation of Microsoft's Warbird obfuscation

Curated collection of security conference slides and talks on game console exploitation, kernel vulnerabilities, and sandbox escapes.

A PoC of the CVE-2024-56426 vulnerability.

POC of CVE-2023-35086 only DoS

[CVE-2017-10235] Description and PoC of VirtualBox E1000 device Buffer Overflow

An implementation of CVE-2016-0974 for the Nintendo Wii.

Black-box security evaluation of five ISP cable modem/router gateways, analyzing firmware images and documenting 35+ vulnerabilities including…

A collection of my public security advisories.

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

The results of my small term paper on the topic of the Internet of Vulnerable Things and the exploit for CVE-2022-48194.

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

Bitcoin Cryptanalysis: CVE-2025-27840 Vulnerability in ESP32 Microcontrollers Puts Billions of IoT Devices at Risk via Wi-Fi & Bluetooth