
Zapscape
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

Your agent is a security risk, so treat it like one. yoloAI does AI agent sandboxing right.

Qubes containerization on Windows

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape

Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Go Trusted Execution Environment (TEE)

GoTEE - example application

Domain-specific language for writing fast functional device models for virtual platforms. Compiles DML to C with API calls tailored for the Intel…

Official QEMU mirror. Please see https://www.qemu.org/contribute/ for how to submit changes to QEMU. Pull Requests are disabled. Please only use…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Microsoft's curated repository of secure boot objects (KeK, Db, Dbx) for firmware and runtime, enabling transparent revocation updates and…

Lord Of Active Directory - automatic vulnerable active directory on AWS

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…