
CVE-2025-1974
In-depth technical analysis of CVE-2025-1974 (IngressNightmare), a critical RCE in ingress-nginx validating admission controller for Kubernetes,…

In-depth technical analysis of CVE-2025-1974 (IngressNightmare), a critical RCE in ingress-nginx validating admission controller for Kubernetes,…

Kubernetes gitRepo volume vulnerability (CVE-2024-10220) exploit for controlled HPC security research, demonstrating arbitrary command execution on…

Cryptographically signed, replay-verifiable evidence layer for AI agents. Governs actions in the loop, produces Ed25519-signed receipts linked into a…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

POCs and Tetragon Rules for CVE-2024-21626 and CVE-2025-31133

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…


PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…