Featured

Pentesting

New 2026

Vulnerability assessment and penetration testing of Metasploitable2 in an isolated VMware laboratory environment.

New 2026

Sandbox escape PoC for iOS 26 and 27.

New 2026

Pre-authentication RCE in Cisco CUCM 15.x via Apache Axis JNDI injection — independent chain, survives Silent;Call patches

New 2026

Pre-authentication SIP request smuggling in Cisco Expressway X14.x via Content-Length integer overflow

New 2026

Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers.

New 2026

AuditSentry — AI-powered smart contract security auditor for Claude Code. Automated vulnerability detection, exploit PoCs, mainnet-fork simulation, and professional audit reports for Solidity & Vyper across all EVM chains.

New 2026

PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp

New 2026

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, experiments, implementations, findings, and progress made throughout the project, providing a structured overview of the work from basic to advanced stages.

New 2026

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

New 2026

ghostlock exploit for motorola nevada 2026

New 2026

A managed fleet of intentionally-vulnerable apps (Juice Shop, DVWA, WebGoat, VAmPI, crAPI, faultline, and more) to point security scanners and recon tools at. One manager runs each target as its own isolated container stack, with per-app ground-truth vuln catalogs. Local testing only.

New 2026

DJI SkyPixel mc/user/search — 42k+ email enumeration via hardcoded WuKong credentials

New 2026

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

New 2026

Python implementation of OpenPsPipeJack

New 2026

An SPTM bypass for iOS 16 - 17.3.1

New 2026

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence. Includes NtQueueApcThread, NtProtectVirtualMemory, and full payload extraction."

New 2026

Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)