
awesome-ai-security
A collection of awesome resources related AI security

A collection of awesome resources related AI security

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Curated collection of verified patches for the Shellshock (CVE-2014-6271) bash vulnerability, with upstream, Debian, and custom patches plus SHA256…

Curated collection of resources and analysis documenting the CVE-2024-3094 supply-chain backdoor in XZ Utils, including security advisories,…

Curated repository of documented firmware supply chain attacks, featuring IoCs, detection tools, and references to help defenders understand and…

Curated vulnerability writeup collection with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for…

Curated vulnerability writeups with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for real-world software…

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Shell-based scanner to detect the XZ Backdoor (CVE-2024-3094) vulnerability in files and directories, enabling rapid identification and mitigation of…

Portable security rules for the action boundary of AI agents

List of company advisories log4j

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

Hashes for vulnerable LOG4J versions

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Shell script to detect the CVE-2024-3094 backdoor in XZ Utils by checking for malicious code in liblzma build artifacts and identifying affected…

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…