
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover
A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

📦 Make security testing of K8s, Docker, and Containerd easier.

Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…

Automated Persistence and Lateral Movement using GCP Patch Management

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

Android Remote Access Trojan

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration