
CVE-2026-64638
Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…
code-analysisexploitationpayload-development+4

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Collection of tools to use with Azure Applications

macOS Initial Access Payload Generator

USBCoercer turns an ESP32 development board with native USB-OTG into an Ethernet-over-USB gadget capable of coercing proxy configuration via WPAD.

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

C2 Powershell Command & Control Framework with BuiltIn Commands

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.