
slides
Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

simple application with a (unreachable!) CVE-2022-45688 vulnerability

simple application with a (unreachable!) CVE-2022-45688 vulnerability

LSTM-based classifier for detecting domain generation algorithm (DGA) domains, with Keras implementations of neural network and bigram models for DNS…

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…

A LSTM based framework for handling multiclass imbalance in DGA botnet detection

Research Regarding CVE-2019-0708.

CVE-2025-20352 Research writeup

CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Technical write-up and PoC for CVE-2026-24009, demonstrating unsafe YAML loading in docling-core and practical mitigation paths.

PoC for CVE-2025-62518 demonstrating tar archive smuggling via tokio-tar PAX header parsing, creating malicious payloads and a vulnerable extractor…

Artica Proxy before 4.30.000000 Community Edition allows Reflected Cross Site Scripting.