
Awesome-MoAI-Security
Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

Proof-of-concept exploit for CVE-2026-21055 demonstrating arbitrary command execution via improperly exported Android components in Samsung Bixby.…

Technical writeup analyzing CVE-2024-20154, a stack-based buffer overflow in MediaTek MT6769 NB-IoT baseband firmware, covering reverse engineering…

CVE-2025-48593

Pixnapping Attack: Compromising private keys and seed phrases through vulnerability CVE-2025-48561 represents a new critical threat to the Bitcoin…

Use own Phone to DoS Attack without Termux! (Android 5.1+)


Bluetooth keystroke injection exploit PoCs for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 targeting Android, Linux, macOS, and iOS via…

Android Application Task Hijacking Aka Strandhogg Attack Exploit

A fully public exploit of the CVE-2020-0022 BlueFrag Android RCE Vulnerability (tested on Pixel 3 XL)

Extracts and investigates infrastructure (IPs, domains) from APK files, with manifest parsing and WHOIS lookup for mobile application reconnaissance.

Mobile camera-based application that attempts to alter photos to preserve their utility to humans while making them unusable for facial recognition…

THIS TOOL IS FOR DDOS ATTACK ON PHONE NUMBER YOU CAN USE THIS TOOL ON YOUR KALI LINUX OR TERMUX ALSO IF IS NOT WORK THEN PLEASE CONTACT ME IN…

SSH brute-force tool targeting jailbroken iPhones with default 'alpine' password, featuring network scanning, wordlist-based cracking, and file…

Android SystemUI privilege escalation exploit for CVE-2020-0114, demonstrating a hidden call function attack surface with proof-of-concept code.

Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories.