
jiopc-architecture-whitepaper
Technical whitepaper dissecting JioPC cloud VDI architecture, including hardware specs, session termination mechanisms, and security limitations,…

Technical whitepaper dissecting JioPC cloud VDI architecture, including hardware specs, session termination mechanisms, and security limitations,…

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel vulnerability affecting multiple distributions, with tested versions and a technical…

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel vulnerability affecting multiple distributions, with a technical writeup and tested…

Technical writeup and proof-of-concept for CVE-2026-31431, a Linux kernel vulnerability affecting multiple distributions, with tested versions and…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

SSRF (Server Side Request Forgery) testing resources

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

A collection of my public security advisories.

Issue with tough, versions prior to 0.20.0 (Multiple CVEs)

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

OWASP Ontology-driven Threat Modelling framework