
bomber
Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Curated repository of documented firmware supply chain attacks, featuring IoCs, detection tools, and references to help defenders understand and…

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

Curated dataset of cloud middleware agents installed by AWS, Azure, and GCP, documenting past vulnerabilities, privileges, and attack-surface risks…

Demonstration of CVE-2017-1000117: a Git vulnerability triggered by recursive cloning of malicious submodules, causing arbitrary command execution.

Collection's of Tech Talk that are presented by me :)

Semantic graph-based version control for AI-written code. Tracks entities and relations instead of file diffs, enabling blast radius analysis, shadow…

A documentation and tracking project with the goal of making package management systems more secure.

Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security…

Builds a SQLite database of Maven artifacts (ArtifactID, GroupID, Version, SHA1) for Trivy's Java component vulnerability detection, enabling scans…

Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and…

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and…

AI Security Newsletter - A monthly digest of AI security research, insights, reports, upcoming events, and tools & resources

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…