
guac
Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

Open source vulnerability DB and triage service.

Agent-Isolated Credential Broker for AI Agents


Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

AURORA demo target — deliberately vulnerable lockfiles (CVE-2019-10744, CVE-2018-18074, CVE-2020-26160)

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…



End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228