apex v2.4.0-canary.d5c18874
AI-powered offensive security testing using autonomous agents, directly in your terminal.
Read more...
AI-powered offensive security testing using autonomous agents, directly in your terminal.
Read more...
cloudprober v0.14.5
An active monitoring software to detect failures before your customers do.
Read more...
An active monitoring software to detect failures before your customers do.
Read more...
DakshSCRA v0.38-beta
Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines.
Read more...
Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines.
Read more...
AppEnumGuard v1.2
CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1
Read more...
CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1
Read more...
httrack v3.49.24
Offline website copier that recursively downloads HTML, images, and files to create a browsable local mirror, with support for resuming and updating existing mirrored sites.
Read more...
Offline website copier that recursively downloads HTML, images, and files to create a browsable local mirror, with support for resuming and updating existing mirrored sites.
Read more...
promptfoo v0.122.1
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
Read more...
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
Read more...
semgrep v1.175.0
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Read more...
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Read more...
SkillSpector v2.10.0
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Read more...
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Read more...
ApplicationInspector v1.10.1
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
Read more...
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
Read more...
The Bug Bounty Hunter’s Guide to Prototype Pollution
Finding and Breaking .Js prototype for the devs to fix.Continue reading on MeetCyber »
Read more...
Finding and Breaking .Js prototype for the devs to fix.Continue reading on MeetCyber »
Read more...
Medium
The Bug Bounty Hunter’s Guide to Prototype Pollution
Finding and Breaking .Js prototype for the devs to fix.
Unauthenticated Full User Directory PII Dump — 103K+ Records Exposed
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
Unauthenticated Full User Directory PII Dump — 103K+ Records Exposed
Introduction
sandbox-runtime v0.0.74
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
Read more...
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
Read more...
A bug bounty is not a control you buy, it is a queue you have to staff
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…Continue reading on Medium »
Read more...
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…Continue reading on Medium »
Read more...
Medium
A bug bounty is not a control you buy, it is a queue you have to staff
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…
Account Takeover via Parameter Confusion in Login Authentication
One day, while testing an application, I came across a relatively simple login flow.Continue reading on Medium »
Read more...
One day, while testing an application, I came across a relatively simple login flow.Continue reading on Medium »
Read more...
Medium
Account Takeover via Parameter Confusion in Login Authentication
One day, while testing an application, I came across a relatively simple login flow.
cottage v0.7.0
https://kitploit.com/en/posts/github-sayanarijit-cottage-v070
A modern git based age-encrypted secrets manager for teams.
https://kitploit.com/en/posts/github-sayanarijit-cottage-v070
A modern git based age-encrypted secrets manager for teams.
cdncheck v1.2.50
https://kitploit.com/en/posts/github-projectdiscovery-cdncheck-v1250
A utility to detect various technology for a given IP address.
https://kitploit.com/en/posts/github-projectdiscovery-cdncheck-v1250
A utility to detect various technology for a given IP address.
cli v1.1307.0
https://kitploit.com/en/posts/github-snyk-cli-v113070
Snyk CLI scans and monitors your projects for security vulnerabilities.
https://kitploit.com/en/posts/github-snyk-cli-v113070
Snyk CLI scans and monitors your projects for security vulnerabilities.