
CVE-2025-24054_CVE-2025-24071-PoC
Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071

Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

Autoencoder-based anomaly detection for identifying phishing domains using CERT Polska warning list data, with Jupyter notebooks for research and…

Security advisory detailing a critical CVE in Copilot AI where RAG-based citation links are forged to a third-party domain, enabling source…

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

😱 A curated list of amazingly awesome OSINT

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

A curated list of useful resources that cover Offensive AI.

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.