
PHP-8.1.0-dev-Backdoor
PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Supply-chain Levels for Software Artifacts

The Most Comprehensive Docker Security Scanner

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.


Smart Tree: not just a tree, a philosophy. A context-aware, AI-crafted replacement for 20+ tools with MEM8 quantum compression, semantic search,…

EU AI Act Compliance Tool - Risk classification and bias testing

AI coding agents that can't exfiltrate secrets or merge their own PRs.

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks

Information for CVE-2024-3094