
CVE-2026-19745
Learn how I found my first two CVEs by pure accident.

Learn how I found my first two CVEs by pure accident.

Educational Python simulation demonstrating ECDSA nonce reuse in IoT firmware signing, showing how an attacker can recover private keys from two…

Proof-of-concept and writeup showing how to retrieve Wi-Fi SSID/password from a D-Link Komfy smart switch over BLE by reversing the iOS app’s custom…

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

CVE-2025-57174 Unauthenticated Remote Command Execution

Or how I turn off my TV via a cronjob

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

Bitcoin Cryptanalysis: CVE-2025-27840 Vulnerability in ESP32 Microcontrollers Puts Billions of IoT Devices at Risk via Wi-Fi & Bluetooth

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

Reverse Engineering of the Shining App Mask

Manipulate Chromecast Devices in your Network

IoTGoat is a deliberately insecure firmware based on OpenWrt.

Attack Surface Discovery tool built on a microservice approach, utilizing multi-threading for fast, internet-scale asset indexing

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Curated collection of open specifications for AI-integrated vehicle systems, covering autonomy, perception, navigation, energy management, safety,…