
CVE-2025-43529
Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.

Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.

Experiments related to CVE-2015-3456

Private keys vulnerable to Debian OpenSSL bug (CVE-2008-0166)

A collection of scripts and documents to help future XProtect Remediator (XPR) research

This repository is to provide a write-up and PoC for CVE-2023-41717.

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks

Proof Of Concept for Android. NoFrak is designed to prevent fracking attacks, as described in "Breaking and Fixing Origin-Based Access Control in…

Python script to generate neo4j Cypher representation of a collection of IoT devices for visualisation and query.

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

A small write-up with examples to understand CVE-2023-43115

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)

This repository hosts a multimodal web attack dataset (MWAD) to advance AI-driven threat detection research.

Security Advisory: Out-of-Bounds Read in facil.io MIME Parser leads to Server crash

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics,…

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…