
CVE-2026-26897-EcoOnline-DeepLink
Public advisory & PoC for CVE-2026-26897 — Deep Link Bypass in EcoOnline EHS Android (com.airsweb.v10), fixed in 0.2.500

Public advisory & PoC for CVE-2026-26897 — Deep Link Bypass in EcoOnline EHS Android (com.airsweb.v10), fixed in 0.2.500

Automated man-in-the-middle attack tool.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Tools and Techniques for Red Team / Penetration Testing

People tracker on the Internet: OSINT analysis and research tool by Jose Pino

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

Curated collection of recipes for DFIR, malware deobfuscation, and data transformation, with regex patterns, decoding workflows, and incident…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names