
CVE-2026-0848
nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

CVE-2026-40175

Advisory for pdf-image ⌯⌲ 10 000 weekly downloads

Advisory for textract ⌯⌲ 15 000 weekly downloads

Working implementation: cryptographically verified short-lived identities for AI decision authentication — CVE-2025-59536 (Patent Pending US…

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

CVE-2025-48384 PoC

Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Getting a handle on container security

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Source code for the Binaries of OWASP WrongSecrets