
training-application-security
Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Security training for the apps you actually ship. Open your browser and start hacking.

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

Proof-of-concept demonstrating arbitrary command execution via malicious virtual environment activation scripts in PyCharm before 2020.3.4,…

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

Proof-of-concept exploit demonstrating a GitHub OAuth token-stealing vulnerability via crafted developer workflow triggers, enabling unauthorized…

spring retry 1.3.x fix with niche toolkit for CVE-2026-41710

Technical analysis and Proof-of-Concept (PoC) for a critical Path Traversal vulnerability via Symlink manipulation in the Node.js 'tar' package…

patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Collect VEX documents and update VEX Hub

CVE-2024-38526 - Polyfill Scanner

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.