
CVE-2018-12533
Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

Proof-of-concept and disclosure pack for CVE-2026-19952, an unauthenticated arbitrary file deletion in the WordPress Frontend Admin plugin, with lab…

Hybrid machine-learning pipelines for detecting SQL injection in web traffic, combining DistilBERT and BERT-GNN models with adversarial training and…

Specialized reasoning LLM for source-code vulnerability detection in C/C++ and Python, with dataset construction, SFT/DPO training, and…

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

[NeurIPS '25] Code for Paper "IF-Guide: Influence Function-Guided Suppression of Harmful Training Data for Reducing LLM Toxicity"

Detects LLM context-leakage attacks by training lightweight behavior probes on log-probabilities, with vLLM offline/server detection pipelines.

Research pipeline for detecting latent indirect prompt-injection exposure signals in agentic LLMs via hidden-state probing, including trace…

Detailed analysis and proof-of-concept for CVE-2021-44228 (Log4j RCE), including environment setup, vulnerability analysis, JNDI injection mechanism,…

Proof-of-concept testing environment for CVE-2021-30858, based on Google Project Zero's root cause analysis of an in-the-wild iOS exploit.

A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software…

Writeup for CVE-2021-35475; Stored Cross-Site Scripting(XSS) on SAS® Environment Manager 2.5

Fully automatic censorship removal for language models

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)

CVE-2026-34038: Authenticated Remote Command Injection in Coolify