
red-teaming-auto-mode
Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…

Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…

Docker lab reproducing CVE-2026-42533, a pre-auth nginx heap overflow and info leak via two-pass capture clobbering, with PoC scripts and patched…

PJSIP DNS Compression Pointer Heap OOB Read (Remote DoS)

Reproducible lab for CVE-2026-23398, a Linux kernel NULL dereference in icmp_tag_validation() triggered by ICMP Fragmentation Needed packets, causing…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Fully dockerized Linux kernel debugging environment

AArch64 fuzzer based on the Apple Silicon hypervisor

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

EF/CF - Extremely Fast smart Contract Fuzzing

A fuzzer for full VM kernel/driver targets

Lightweight fuzzing of a memory snapshot using KVM

Differential testing framework for HTTP implementations

A collection of links related to VMware escape exploits

A GPU-oriented coverage-guided fuzzer for userland CUDA applications

CVE-2026-23918 Apache mod_http2 Double-Free Detector

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…