
OMLASP
Framework for auditing machine learning algorithms against adversarial attacks and biases, providing educational tools and an academic paper to…

Framework for auditing machine learning algorithms against adversarial attacks and biases, providing educational tools and an academic paper to…

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

An Evaluation Agent for Detecting Misinformation and Knowledge Poisoning in Retrieval-Augmented Generation Systems.

nextpnr portable FPGA place and route tool

Heap-based buffer overflow example based on CVE-2023-4504

Centralized YAML-based knowledge base linking MITRE CWE, OWASP Top10, ASVS, and other security standards with versioned references. Includes MkDocs…

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Proof-of-concept testing environment for CVE-2021-30858, based on Google Project Zero's root cause analysis of an in-the-wild iOS exploit.

Awesome-Cellular-Hacking

An automatic obfuscation tool for Android apps that works in a black-box fashion, supports advanced obfuscation features and has a modular…

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

OWASP Smart Contract Security (SCS) Project

Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of…

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

CVE-2026-51990 proof-of-concept repository for authorized security research, vulnerability awareness, and defensive testing in isolated lab…

Reproduction project for CVE-2026-16723, a critical RCE in fastjson 1.2.68-1.2.83. Demonstrates AutoType bypass, JNDI injection, and TemplatesImpl…