
wasm2c-tableflip
wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Minimal machine architecture with LLVM compiler backend, Linux port, and virtual machine for creating self-contained software capsules that remain…

Sandbox untrusted code with safe access to the host.

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.


Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

EasySec helps small and medium-sized enterprises (SMEs) with cybersecurity knowledge and resources

Exploit PoC for CVE-2026-64561: KVM/x86 shadow MMU use-after-free allowing a guest to escape to host root. Includes technical write-up, affected…

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape

Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape