
CVE-2026-67595
CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

Documentation and reverse engineering of reCAPTCHA

Finding Java/C# gadget chains with CodeQL

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end…

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Generate malicious files using recently published bidi-attack (CVE-2021-42574)

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

Simple DDE object detector