
cve-2026-54316-lab
Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)


MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

[POC] Asynchronous reverse shell using the HTTP protocol.

Data exfiltration over DNS request covert channel

DNS covert channel implant for Red Teams.

A Powershell client for dnscat2, an encrypted DNS command and control tool.

Universal Dynamic Virtual Channel connector for Remote Desktop Services

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.


Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Decrypted content of eqgrp-auction-file.tar.xz

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Various tips & tricks

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.