New Web Based Subdomain Discovery Service π
crt.name is a new web based service for discovering subdomains through Certificate Transparency (CT) logsπ
It searches publicly available certificate records to identify subdomains associated with a target domainπ΅
Useful forβ
β’ Subdomain Enumeration
β’ Reconnaissance
β’ Asset Discovery
β’ Bug Bounty Recon
crt.nameπ
π @RootAccessClub
π @BugCod3
crt.name is a new web based service for discovering subdomains through Certificate Transparency (CT) logs
It searches publicly available certificate records to identify subdomains associated with a target domain
Useful for
β’ Subdomain Enumeration
β’ Reconnaissance
β’ Asset Discovery
β’ Bug Bounty Recon
crt.name
Please open Telegram to view this post
VIEW IN TELEGRAM
PDF Exploit Defense Toolkit π‘
Two clean, pure-Python tools for handling malicious PDFs:
1οΈβ£ PDF Exploit Scanner
Detects high risk indicators (OpenAction, JS, Launch, XFA, heap spraysβ¦)π€
β‘οΈ Structural patcher + full image based sanitizer included
GitHubπ¨
2οΈβ£ IP Scanner for Exploited PDFs
Pulls hidden IPs/ranges from hijacked PDFs (byte-level)π€
β‘οΈ Scans common ports + temporary firewall to block them
GitHubπ¨
π© @RootAccessClub
Two clean, pure-Python tools for handling malicious PDFs:
Detects high risk indicators (OpenAction, JS, Launch, XFA, heap spraysβ¦)
GitHub
Pulls hidden IPs/ranges from hijacked PDFs (byte-level)
GitHub
Please open Telegram to view this post
VIEW IN TELEGRAM
DroneSploit β Opensource Metasploit alternative for drone pentesting π
GitHubπ±
π @RootAccessClub
GitHub
Please open Telegram to view this post
VIEW IN TELEGRAM
β‘3
numasec β The open source AI security agent π§
numasec is an AI security agent that runs in your terminalβͺοΈ
It uses the tools already installed on your machine, follows security runbooks, switches between cyber agents, keeps the operation context alive, tracks findings, stores evidence and helps turn the work into reportsπ€
GitHubπ±
π @RootAccessClub
numasec is an AI security agent that runs in your terminal
It uses the tools already installed on your machine, follows security runbooks, switches between cyber agents, keeps the operation context alive, tracks findings, stores evidence and helps turn the work into reports
GitHub
Please open Telegram to view this post
VIEW IN TELEGRAM
β‘3
AutoCVE β One Click CVE Discovery: Select Projects, Audit Source Code, Verify Vulnerabilities, Generate Reports, Fully Automated π₯
GitHubπ
π± @RootAccessClub
GitHub
Please open Telegram to view this post
VIEW IN TELEGRAM
π₯2
PentestCode π₯
AI penetration testing agent in your terminal
Multi-agent architecture Engagement state tracking , 20+ LLM providers β¨
GitHub π
π @RootAccessClub
AI penetration testing agent in your terminal
Multi-agent architecture Engagement state tracking , 20+ LLM providers β¨
GitHub π
π @RootAccessClub
π₯4
How I Found 7 XSS Using a Custom Nuclei Template π¬
Read Here π
#CyberSecurity #BugBounty #xss
β‘οΈ@RootAccessClub
Read Here π
#CyberSecurity #BugBounty #xss
β‘οΈ@RootAccessClub
DarkTortilla RAT β Telegram Exfiltration & Payload Extraction β’
GitHub π
#Payload #CyberSecurity
πͺ @RootAccessClub
GitHub π
#Payload #CyberSecurity
πͺ @RootAccessClub
β‘2
BugScanner π©»
Automated web security reconnaissance & vulnerability assessment tool for bug bounty hunters. Discover attack surfaces, fingerprint technologies, detect common web vulnerabilities, and generate actionable security reports π
GitHub
π@RootAccessClub
Automated web security reconnaissance & vulnerability assessment tool for bug bounty hunters. Discover attack surfaces, fingerprint technologies, detect common web vulnerabilities, and generate actionable security reports π
GitHub
π@RootAccessClub
π₯3
π¦ Stuxnet
A new GitHub project provides an educational reconstruction of the infamous Stuxnet worm, based on years of reverse engineering research into the original 2010 samples π¬
The project explores components such as rootkits, privilege escalation, Step7/S7 hooks, propagation mechanisms, and PLC-related functionality βοΈπ»
π§ͺ Intended for malware analysis, security research, and academic study
GitHub π
π @RootAccessClub
A new GitHub project provides an educational reconstruction of the infamous Stuxnet worm, based on years of reverse engineering research into the original 2010 samples π¬
The project explores components such as rootkits, privilege escalation, Step7/S7 hooks, propagation mechanisms, and PLC-related functionality βοΈπ»
π§ͺ Intended for malware analysis, security research, and academic study
GitHub π
π @RootAccessClub
π₯3β€βπ₯1
PSAITO β New PS5 WebKit Research ToolExperimental toolkit for PS5 π«―
firmware 9.00 β 13.60 β
Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process β¨
Research only β οΈ
GitHub π
π₯@RootAccessClub
firmware 9.00 β 13.60 β
Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process β¨
Research only β οΈ
GitHub π
π₯@RootAccessClub
knife β A reverse engineer's toolkit in Rust πͺ
Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target π―
GitHub π
Β© @RootAccessClub
Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target π―
GitHub π
Β© @RootAccessClub
β€βπ₯2β‘1
Claude Red πͺ
Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant
Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more βοΈ
GitHub π
π‘οΈ@RootAccessClub
Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant
Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more βοΈ
GitHub π
π‘οΈ@RootAccessClub
π₯3
XSS Labsπ¬
An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS
A practical resource for learning how XSS works and how to mitigate it π·οΈ
Github π§ͺ
β‘οΈ @RootAccessClub
An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS
A practical resource for learning how XSS works and how to mitigate it π·οΈ
Github π§ͺ
β‘οΈ @RootAccessClub
β€βπ₯4
CVE-2026-12793 β JetFormBuilder WordPress Plugin π
Critical vulnerability (CVSS 9.8) β οΈ
Affects versions β€ 3.6.2
Unauthenticated privilege escalation
Fixed in version 3.6.2.1 and later β
Attack Flow :
1β£ Detect JetFormBuilder + version β€ 3.6.2 (readme.txt)
2β£ Discover form ID from public pages (data-form-id, /register/, etc.)
4β£ POST to referer page with ?jet_form_builder_submit=submit&method=ajax
4β£ Register User action runs β new WP user created
If you're using this plugin, update immediately βΌοΈ
GitHub ββπ₯
@RootAccessClub
Critical vulnerability (CVSS 9.8) β οΈ
Affects versions β€ 3.6.2
Unauthenticated privilege escalation
Fixed in version 3.6.2.1 and later β
Attack Flow :
1β£ Detect JetFormBuilder + version β€ 3.6.2 (readme.txt)
2β£ Discover form ID from public pages (data-form-id, /register/, etc.)
4β£ POST to referer page with ?jet_form_builder_submit=submit&method=ajax
4β£ Register User action runs β new WP user created
If you're using this plugin, update immediately βΌοΈ
GitHub ββπ₯
@RootAccessClub
OWASP Amass π
An open source framework for network mapping and attack surface discovery
β’ Subdomain & DNS enumeration
β’ OSINT-based asset discovery
β’ Infrastructure mapping
β’ External attack surface analysis
Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters βοΈ
GitHub π
π @RootAccessClub
An open source framework for network mapping and attack surface discovery
β’ Subdomain & DNS enumeration
β’ OSINT-based asset discovery
β’ Infrastructure mapping
β’ External attack surface analysis
Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters βοΈ
GitHub π
π @RootAccessClub
π₯2
Legion β Automated Network Pentesting π‘οΈ
Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery
πΈ Nmap, Nikto, WhatWeb, Hydra, SMBenum
πΉ CVE & vulnerability mapping
πΈ Automated scanning & enumeration
Github π
π‘ @RootAccessClub
Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery
πΈ Nmap, Nikto, WhatWeb, Hydra, SMBenum
πΉ CVE & vulnerability mapping
πΈ Automated scanning & enumeration
Github π
π‘ @RootAccessClub
β€βπ₯2
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain π₯
Unauthenticated Arbitrary File Read β Admin Token Forge β Sandbox Bypass β RCE πͺ
CVSS : 10.0 + 9.9 (Critical) β οΈ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) β
Github π
πͺ @RootAccessClub
Unauthenticated Arbitrary File Read β Admin Token Forge β Sandbox Bypass β RCE πͺ
CVSS : 10.0 + 9.9 (Critical) β οΈ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) β
Github π
πͺ @RootAccessClub
β€βπ₯1
Osintgram π₯
An open source OSINT framework for Instagram reconnaissance and information gathering π
Key Features:
β’ Profile & content analysis
β’ Followers / Following analysis
β’ Hashtag & location searches
β’ Media and metadata analysis
β’ Account comparison
β’ Interactive Web UI
β’ AI assisted mode with local Ollama support
β’ JSON & HTML report generation
GitHub π
β οΈ Use responsibly and only with data you are authorized to investigate
π @RootAccessClub
An open source OSINT framework for Instagram reconnaissance and information gathering π
Key Features:
β’ Profile & content analysis
β’ Followers / Following analysis
β’ Hashtag & location searches
β’ Media and metadata analysis
β’ Account comparison
β’ Interactive Web UI
β’ AI assisted mode with local Ollama support
β’ JSON & HTML report generation
GitHub π
β οΈ Use responsibly and only with data you are authorized to investigate
π @RootAccessClub
β€βπ₯4
WordPress Critical RCE π¨
CVE-2026-87902 | CVSS 9.2 π«―
A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution π£
Affected versions span 4.7 β 7.1.1 π¦
π‘οΈ Fix: Update to the latest patched WordPress release for your branch
GitHub π
@RootAccessClub
CVE-2026-87902 | CVSS 9.2 π«―
A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution π£
Affected versions span 4.7 β 7.1.1 π¦
π‘οΈ Fix: Update to the latest patched WordPress release for your branch
GitHub π
@RootAccessClub
π₯2
Root Access Club
WordPress Critical RCE π¨ CVE-2026-87902 | CVSS 9.2 π«― A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution π£ Affected versions spanβ¦
CVE-2026-87902 π§ͺ
WordPress unauthenticated LFI β conditional RCE π
Github π
β οΈ Authorized security testing, education, and defensive research only
π @RootAccessClub
WordPress unauthenticated LFI β conditional RCE π
Github π
β οΈ Authorized security testing, education, and defensive research only
π @RootAccessClub
π₯2