

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE


nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…



End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

AURORA demo target — deliberately vulnerable lockfiles (CVE-2019-10744, CVE-2018-18074, CVE-2020-26160)

Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701


Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Agent-Isolated Credential Broker for AI Agents

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…