
netlas-cookbook
The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Learn how I found my first two CVEs by pure accident.

The vulnerable application that will teach you how to hack WebSockets

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Owa Valid Login Checker

CVE-2026-0073 is an RCE with a CVSS severity score of 8.3, and here we will explain how it works.

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

I Found a Zero-Day Vulnerability in langchain — Here’s How It Went

Tests your WAF with +160 payloads

Proof-of-concept for CVE-2026-25940 demonstrating embedded JavaScript execution via crafted AcroForm radio button appearances in PDF viewers, with…

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

CVE‑2025‑55182 Detection

Meow

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

A OSINT project that explores how to dump data from React