CVE-2025-32953
: Exposure of the GITHUB_TOKEN in workflow run artifact in udo-munk/z80packCVE-2025-32958
: Adept exposed the GITHUB_TOKEN in workflow run artifact in AdeptLanguage/AdeptCVE-2025-46820
: phpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifact in phpgt/DomGHSA-h4c9-2c5c-fwfc
: Github Token Compromise in Pex Repository in pex-tool/pexGHSA-h6rw-378w-jf2v
: Leaking of High Permission GITHUB_TOKEN in Workflow Artifact in openebs/mayastorGHSA-w4f2-8vv5-2338
: Leaking of High Permission GITHUB_TOKEN in Workflow Artifact in openebs/mayastor-control-planeGHSA-8ffm-p88r-g625
: pendingGHSA-535w-4488-jc7p
: pendingGHSA-35g9-52wf-83hw
: pendingGHSA-q656-gjrm-9mh5
: pendingGHSA-f78v-x25j-8x42
: pending- Apache Security Team Credit
- nginx/F5 Credit
🤘
I’m an Offensive Security Engineer that likes to research interesting security topics and break stuff.
- Canada
- https://nopcorn.run
Pinned Loading
-
DuckDuckC2
DuckDuckC2 PublicA proof-of-concept C2 channel through DuckDuckGo's image proxy service
-
RascalRunner
RascalRunner PublicA red team tool to leverage Github workflows and self-hosted runners
Python 6
-
githubaudit
githubaudit PublicUses a Github PAT to assess the security configuration of repositories and provides a report
Python 1
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.