
heretic
Fully automatic censorship removal for language models

Fully automatic censorship removal for language models

Research pipeline for detecting latent indirect prompt-injection exposure signals in agentic LLMs via hidden-state probing, including trace…

Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Artifacts for the USENIX publication.

awslabs/sockeye Code injection via unsafe YAML loading CVE-2021-43811

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

Active Scanning and Information Gathering in ICS/SCADA Networks using Network Mapper (NMAP) (Turkish)

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

CVE-2025-45407: Multiple XSS Vulnerabilities in DiscoveryNG v6.0.8 Hotfix 2 Discovered by: YallaSec Security Research Team CVE ID: CVE-2025-45407…

Key Negotiation Of Bluetooth (KNOB) attacks on Bluetooth BR/EDR and BLE [CVE-2019-9506]

Detailed technical analysis of CVE-2025-43300, a buffer overflow vulnerability in DNG file processing enabling remote code execution. Explains the…

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

Research implementation for mitigating adaptive prompt injections via on-policy distillation, with training recipes and evaluators for SEP, PISmith,…

Detects LLM context-leakage attacks by training lightweight behavior probes on log-probabilities, with vLLM offline/server detection pipelines.

Technical analysis of CVE-2025-0924, a Stored XSS vulnerability in WP Activity Log plugin for WordPress. Includes root cause analysis, exploitation…

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

This repository is developed to analysis and understand DirtyPipe exploit CVE-2022-0847