g3n3r4l20
-
Searchlight Cyber Threat Intelligence Tools (tools.slcyber.io)
Comprehensive suite for digital risk monitoring and dark web investigations. SLCyber
-
Monero Network 51% Attack Incident (web3isgoinggreat.com)
Blockchain security compromised through majority hash-rate manipulation. Web3IsGoingGreat
-
Zigot Ransomware Reverse Challenge (vx.zone)
CTF exercise focused on ransomware binary analysis and decryption techniques. VX-Zone
-
Wiz Emoji Security Cheat Sheets (wiz.io)
Visual guides for cloud security concepts using custom "Wizmoji" icons. Wiz
-
Debian 100K Milestone Celebration (lists.debian.org)
Historic project anniversary reflecting on open-source longevity. Debian
-
Anthropic Red Team Research Portal (red.anthropic.com)
AI safety testing resources and adversarial research findings. Anthropic
-
Lessons from Building an AI Hacker (AIxCC) (theori.io)
Theori's insights from participating in DARPA’s AI Cyber Challenge. Theori
-
GitHub Copilot: Remote Code Execution via Prompt Injection (embracethered.com)
Demonstration of how prompt injection in GitHub Copilot could lead to RCE scenarios. EmbraceTheRed
-
Data Exfiltration via Image Rendering Fixed in Amp Coded (embracethered.com)
Explains a vulnerability allowing exfiltration via maliciously rendered images. EmbraceTheRed
-
From Support Ticket to Zero Day (horizon3.ai)
Real-world exploit chain research from Horizon3.ai showcasing how simple bugs evolve into zero-days. Horizon3.ai
-
Cracking the Vault: HashiCorp Vault 0-days (cyata.ai)
Discovery of critical zero-day vulnerabilities in authentication and identity mechanisms of HashiCorp Vault. Cyata
-
Ostorlab: Signal Arbitrary File Read Vulnerability (blog.ostorlab.co)
Detailed analysis of an arbitrary file read vulnerability in Signal, discovered via mobile app testing. Ostorlab
-
LLM Reward Hacking Exploits (medium.com)
Manipulating model incentives to bypass alignment safeguards. Medium
-
Veeam CVEs and Bounty Disclosures (blog.voorivex.team)
Critical vulnerabilities revealing $30K bounties in backup systems. Voorivex
-
Gmail Phishing Scam Analysis (malwr-analysis.com)
Emerging credential theft campaign using deceptive forwarding rules. Malwr
-
Python Wheel Archive Confusion Fix (blog.pypi.org)
Mitigating malicious ZIP parser exploitation in installers. PyPI
-
LLM-Powered Patch Diffing Research (bishopfox.com)
AI-assisted vulnerability discovery through commit analysis. BishopFox
-
Autonomous Pentesting with Hacktron (hacktron.ai)
AI agent conducting full security audits without human intervention. Hacktron
-
FortiSIEM Pre-Auth RCE Exploit (labs.watchtowr.com)
CVE-2025-25256 exposing critical command injection flaw. WatchTowr
-
Demystifying Burp AI Functionality (parsiya.net)
Gain insight into How Burp AI Works through this detailed blog post. Parsiya
X1
-
Crypto wallet drained via compromised VS Code plugin. X.com
y0utube1
-
Deserialization Vulnerability Deep Dive (youtube.com)
Exploiting insecure object serialization in web apps. YouTube
g1thub12
-
Spotter: Kubernetes Security Scanner (github.com)
CEL-powered scanner for Kubernetes clusters, manifests, and CI/CD environments. GitHub
-
Cybersecurity Simulation Handbook (github.com)
Red team tactics and adversary emulation playbooks. GitHub
-
Black Hat USA 2025 Presentations (github.com)
Conference slides for offensive security research. GitHub
-
GitLab Attack Toolkit (GLATO) (github.com)
Framework for auditing GitLab instance security. GitHub
-
CI/CD Pipeline Sentinel Scanner (github.com)
Detecting misconfigurations in DevOps workflows. GitHub
-
Burp Suite Recursive Request Exploit (github.com)
DEFCON tool for chained vulnerability exploitation. GitHub
-
Google's Camel Anti-Injection Framework (github.com)
Prompt injection countermeasures for LLMs. GitHub
-
OSINT Footprint Search Tool (github.com)
Cross-platform username reconnaissance across 300+ sites. GitHub
-
Pentest Reporting ZSH Theme (github.com)
Custom terminal with integrated command logging. GitHub
-
AI-Driven AD Password Sprayer (github.com)
Targeted credential attacks using user intelligence. GitHub
-
HexStrike AI Pentesting Agents (github.com)
Autonomous cybersecurity tools orchestration via LLMs. GitHub
-
DNS Takeover Methodology Guide (github.com)
Provider-specific techniques for domain reclamation. GitHub