Reach 125K+ monthly visitors

Advertise on Trendshift

Pentesting

New 2026

A foundational C library for building operationally credible offensive capabilities

New 2026

One-command security scanner. 40+ rules for secrets, OWASP and deps. Scanned React: F grade.

New 2026

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.

New 2026

IOC enrichment + PE static analysis in one self-contained Windows CLI. Zero dependencies.

New 2026

BruceButBetter — DIY Flipper Zero on ESP32-S3 N16R8. Downstream Bruce fork: Sub-GHz, NFC/RFID, IR, WiFi/BLE, NRF24 & Si5351 in one device. Browser flasher included.

New 2026

PenTest Toolkit v2 is a fully async, plugin-based security testing framework designed specifically for real-world bug bounty hunting. Every module is independently runnable, outputs structured JSON findings, and feeds into a unified HTML report with optional AI-powered analysis.

New 2026

Free web reconnaissance tool for bug bounty hunters and pentesters — by Sipar Security

New 2026

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

New 2026

Autonomous decentralized AI OSS hardener. Core Rust/P2P/zero-trust, Python AI/ML, C++23 perf. MVP: Scanner (graph DB + GNN-ready risk/neglect scoring) + Knowledge (IPFS/RAG-ready). Permissive OSS.

New 2026

Security and privacy guardrails for AI-assisted software development

New 2026

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data straight from disk.

New 2026

Payload injector and HID emulator for Android

New 2026

Cacti ≤ 1.2.30 Auth RCE - Host variable injection

New 2026

SoK/Whitepaper on Offensive Operations against Active Directory Certificate Service

New 2026

Deep paint osint tool

New 2026

Smuggling C2 comms through links previews

New 2026

Activation Context Hijacking Evasion Tool

New 2026

Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.

New 2026

🛡️ Duolingo for Cybersecurity — Track TryHackMe progress, earn XP, unlock achievements, and follow guided learning paths.

New 2026

A Claude Code skill that security-audits vibe-coded SaaS apps. 50 common ways AI-generated apps get pwned, turned into a repeatable checklist, severity scoring, and findings report!