
akto
Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Secure agents in seconds with permissions enforced at runtime.

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Admission control and runtime guardrails for agentic AI. Scans skills, MCP servers, plugins, and code before execution; inspects prompts,…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Static binary rewriter that instruments XNU kernel and kexts, enabling targeted function/file-level coverage and feedback-aware fuzzing for macOS…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

Operational security controls with forensic guarantees

Reproducer for CVE-2026-46456: Apache Camel camel-aws2-sqs inbound message-attribute header injection enabling downstream producer steering and RCE…

Reproducer for CVE-2026-46592 demonstrating SOAP operation redirection via operationName header injection in Apache Camel camel-cxf, enabling…

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Reproducer for CVE-2026-46455 demonstrating Apache Camel camel-keycloak authentication bypass via missing TokenVerifier.IS_ACTIVE check, allowing…

Reproducer for CVE-2026-46726 demonstrating WebSocket header injection in Apache Camel camel-vertx-websocket enabling SSRF and property-placeholder…

Reproducer for CVE-2026-49099 demonstrating SOQL injection via HTTP header override in Apache Camel camel-salesforce, with mock Salesforce backend…