
adm-zip_LPE-PoC
CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction

CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction

Proof-of-concept exploit for CVE-2025-69599, demonstrating uncontrolled search path element in RayVentory Scan Engine's rvia and ndtrack binaries,…

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Proof-of-concept exploit for CVE-2025-69604, demonstrating privilege escalation via malicious package installation in SuperDuper backup tasks on…

Proof-of-concept exploit for CVE-2023-1521 demonstrating LD_PRELOAD-based privilege escalation in sccache, enabling arbitrary code execution during…

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.


A vulnerability scanner for container images and filesystems

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…