
bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

A collection of awesome resources related AI security


Scanners for Jar files that may be vulnerable to CVE-2021-44228

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Hashes for vulnerable LOG4J versions


This is an incident response playbook we created for the Vercel April 2026 compromise

Portable security rules for the action boundary of AI agents

Find log4j for CVE-2021-44228 on some places * Log4Shell

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…


Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

GitHub Actions workflow sandbox for CVE-2026-45132 reproduction

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y…