
polytracker
An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Defund the Police.

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Academic research on N-Day Linux kernel vulnerabilities, analyzing CVE-2024-36886 in the TIPC networking subsystem, lifecycle, impact, and mitigation…

GNU IFUNC is the real culprit behind CVE-2024-3094

Detailed write-up and proof of concept for CVE-2023-41717, demonstrating bypass of Zscaler proxy file download/upload restrictions via HTTP Range…

A tool for effective testing the binding layer of scripting languages

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

PoC exploit for CVE-2026-49975 HTTP/2 Bomb DoS vulnerability. Demonstrates HPACK indexed reference bomb combined with flow-control window stall to…

PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6).

Artica Proxy before 4.30.000000 Community Edition allows Reflected Cross Site Scripting.

CVE-2020-15051 : Artica Proxy before 4.30.000000 Community Edition allows Stored Cross Site Scripting.