


Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…

Proof-of-concept exploit demonstrating a GitHub OAuth token-stealing vulnerability via crafted developer workflow triggers, enabling unauthorized…

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

Defense Against the Shai-Hulud Supply Chain Attack

Collect VEX documents and update VEX Hub

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…





This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as…

GitHub Action for Heisenberg SSC