
css-the-bomb-inside-your-inbox
All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

Conference presentation slides

Open standard for documenting security-relevant metadata of AI models, including training data provenance, PII risk, known vulnerabilities, and…

Seemingly normal USB drive with a hidden security feature


A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

Automated defect verification tool for 6 dnsmasq CVEs (CVE-2026-2291, 4890, 4891, 4892, 4893, 5172)

Android security insights in full spectrum.

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

Black-box test whether an LLM chatbot is vulnerable to markdown/HTML exfil (CVE-2025-32711 class). Spins up a sink, sends payloads, renders in…

DLL-injectable internal game cheat for Plutonium BO2 zombies

Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847

Free and Open-Source FRP Remover based on CVE-2022-38694

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔…

Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity

All the deals for InfoSec related software/tools this Black Friday

Curated collection of proof-of-concept vulnerability exploits and research presented at security conferences such as Black Hat and CODE BLUE.