
hpim-training-lab
Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)

Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

A collection of scripts, and tips and tricks for hacking k8s clusters and containers.

PoC exploit for insecure permissions in Contour v1.28.3 that retrieves a Kubernetes service account token and accesses the cluster API, demonstrating…

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

Linux privilege escalation via LXD