
CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration
Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

C# Tool to interact with MS Exchange based on MS docs

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)


Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Phishing with a fake reCAPTCHA

A tool for mapping cyber crime

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

Scripts to clone CA certificates for use in HTTPS client attacks.

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

SEt framework

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.