
advisories
A collection of my public security advisories.

A collection of my public security advisories.


This repository hosts a multimodal web attack dataset (MWAD) to advance AI-driven threat detection research.

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

CLPSTNet: A Progressive Multi-Scale Convolutional Steganography Model Integrating Curriculum Learning

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

A unified framework for privacy-preserving data analysis and machine learning

Firmware security analysis of BD Alaris 8015 infusion pump (CVE-2016-9355). Identified 6 compound vulnerabilities including plaintext Wi-Fi…

Multi-language PoC (Python · Go · JS · C) and technical documentation for CVE-2025-63353, a critical predictable-default-PSK vulnerability in…

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]

[MIRROR] Full CVE-2025-68971 Security Vulnerability Research Report.

A serverless networking protocol designed for resilient state synchronization between autonomous agents in fragmented, low-bandwidth networks

Curated list of CVE-2020-0601 resources

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

Comprehensive research on security vulnerabilities in autonomous maritime vessels and defense recommendations