
Cybersecurity-Mastery-Roadmap
A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

A curated list of resources related to Industrial Control System (ICS) security.

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes…

A list of public penetration test reports published by several consulting firms and academic security groups.

Modular LLM vulnerability scanner that probes for hallucination, data leakage, prompt injection, jailbreaks, and toxicity using static, dynamic, and…


Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Cisco ASA Software and ASDM Security Research

Security advisories by SBA Research.

This repository provides a practical comparison of breach intelligence, dark web monitoring, and identity exposure services, with a focus on factors…

PoC: identify silent security patches before CVE

Educational resource explaining the ethical and technical differences between hackers and crackers, covering vulnerability analysis, system security,…

Active Scanning and Information Gathering in ICS/SCADA Networks using Network Mapper (NMAP) (Turkish)

In-depth technical analysis of Cisco ISE RCE vulnerabilities, including exploitation techniques, evasion methods, and remediation strategies for…

Educational scanner for CVE-2025-55182 (React2Shell) vulnerability detection in React Server Components/Next.js apps. Uses dorks for target discovery…

Unified Security Research Tool

Security research disclosing CVE-2026-9794, an unauthenticated client ID enumeration flaw in Keycloak SAML ECP via faultstring oracle, fixed in…