The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerability in the KVM code that has been sitting there since 2010.
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data destruction (fixed in 4.14.8/4.18.3/4.21.0)
Old CVE, but new way to leak everything.
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
CvE-2026-43499偏移量计算
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
This wizard is built to make life easier when you want to execute a Bluetooth HID exploit against an Android phone and walk away with remote access to it. The exploit itself (CVE-2023-45866, the Bluetooth keyboard impersonation bug) has been around for years and the raw pieces are scattered across the web...
CVE-2026-56164 EOP Exploit
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization
Spring Framework CVE-2022-22965 本地影响条件验证、版本升级修复与复测项目
Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
Formally verified, quantitative reconstruction of the Trivy/TeamPCP GitHub Actions supply-chain attack (CVE-2026-33634): a TLA+/TLC incident model, PRISM probabilistic analysis, and a 189-workflow corpus study.
A containerized enterprise-style lab for researching and defending against CVE-2026-27483.
Writeup de la máquina Snapped (Hard) de Hack The Box. Foothold: CVE-2026-27944 — Nginx UI unauthenticated backup disclosure Privilege Escalation: CVE-2026-3888 — snapd race condition LPE Técnicas: subdomain enumeration, AES decryption, bcrypt cracking, namespace manipulation, dynamic linker hijacking.
CVE-2025-60357- NoSQL(MongoDB) Injection POC
Xiaomi K70e (duchamp) one-click root via CVE-2026-43499 (IonStack) + KernelSU integration
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection