
ironcurtain
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.


Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)


Determine privileges from cloud credentials via brute-force testing.

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

Pivotal CRM's patch for an initial deserialization vulnerability was incomplete. The fix switched from BinaryFormatter to JSON.NET but left…

OWASP Thick Client Application Security Verification Standard

CVE-2026-36522: unauthenticated NaN injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CWE-1287, DoS/integrity)


AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

Technical breakdown of CVE-2026-34473, an unauthenticated denial of service affecting 17+ ZTE router models.