
CVE-2026-25938-FUXA-Unauthenticated-RCE
An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to…

A pre-authenticated RCE exploit for Inductive Automation Ignition

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

Detect Tactics, Techniques & Combat Threats



Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

ICS-Park Smart Park Management System v2.0


Proof-of-concept reproducing CVE-2021-22681's hardcoded-key flaw and validating a per-device mutual TLS/CRL fix over simulated EtherNet/IP, with IEC…

Real world and CTFs exploiting web/binary POCs.

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

Purdue Model for Industrial Control System (ICS) Environments (Turkish)

Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

Python scripts for security assessment of industrial PLCs: scanning, enumeration, control, and exploitation of Beckhoff, Siemens, Schneider,…

Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.