Skip to content

Red Team & Offensive Security

Penetration testing frameworks, exploit tools, and offensive security tooling.

Subscribe
← Releases
Review required
Prowler 5.29.2 Security relevant
Dependencies

Vitest upgrade + UI fixes

Review required
caddy v2.11.4 Security relevant
Auth RBAC

Security patches + deps upgrade

Upgrade now
authentik version/2026.5.2 Security relevant
Auth Breaking upgrade

Security patches + bugfixes

version/2026.2.4 (6d) Security fixes + core updates
Upgrade now
UUSEC WAF v7.2.2 Security relevant
Dependencies

CVE-2026-9256 fix

Upgrade now
authelia v4.39.20 Security relevant
Auth RBAC

Security fixes + contributors + Docker update

Upgrade now
bunkerweb v1.6.11 Security relevant
RCE / SSRF Breaking upgrade

nginx security fix

Upgrade now
NGINX release-1.30.2 Security relevant
RCE / SSRF

Buffer overflow fix

vrelease-1.31.1 (12d) CVE‑2026‑9256 buffer overflow fix
Upgrade now
kanidm v1.10.3 Security relevant
Auth RBAC

Privilege escalation fix

v1.1.2 (16d) GHSA‑g7cv‑rxv3‑hmpx fix
v1 (18d) GHSA‑g7cv‑rxg3‑hmpx
v1.1.1 (18d) Security fix GHSA-g7cv-rxg3-hmpx
v1.1.0 (18d) GHSA‑g7cv‑rxg3‑hmpx fix
Review required
goklab/guardvibe v3.1.25 Security relevant
Dependencies Breaking upgrade

Malicious node-ipc detection + CI npm hardening

Upgrade now
UUSEC WAF v7.2.1 Security relevant
Dependencies

nginx vulnerability fixes

Review required
GlobaLeaks v5.0.93 Security relevant
Auth RBAC

Cross‑tenant security hardening

Upgrade now
kanidm v1.10.2 Security relevant
Auth RBAC

Privilege escalation

v1.9.4 (20d) Privilege escalation
Upgrade now
NGINX release-1.30.1 Security relevant
RCE / SSRF Breaking upgrade

HTTP/2 request injection fix

vrelease-1.31.0 (21d) CVE fixes + forward proxy
Upgrade now
authentik version/2025.12.5 Security relevant
Auth Breaking upgrade

Security patches

Upgrade now
Zeek v8.0.8 Security relevant

MIME header DoS fix

Upgrade now
caddy v2.11.3 Security relevant
Auth RCE / SSRF

Security patches

Upgrade now
qwexvf/aegis-cli v0.17.1 Security relevant
Dependencies

Go 1.26.3 upgrade + retract detection

Prowler 5.26.0 Security relevant
Security fixes
  • CVE-2026-39892 — parser‑mismatch SSRF in image provider registry auth fixed (PR #10945)
  • dep: CVE-2026-33186 — cryptography upgraded from 46.0.6 to 46.0.7
  • dep: CVE-2026-39892 — trivy upgraded from 0.69.2 to 0.70.0
Notable features
  • ASD Essential Eight Maturity Model compliance framework for AWS
  • Eight new Gmail attachment safety and spoofing protection checks for Google Workspace
Splunk Security Content v5.27.0 Security relevant
⚠ Upgrade required
  • Final release for ESCU v5.x; starting with ESCU v6.0, content will be validated, packaged, and published using new internal tooling instead of contentctl.
Security fixes
  • CVE-2026-31431 – Linux Auditd Copy Fail Privilege Escalation detection added to identify unprivileged users writing controlled data to page cache and escalating to root.
Notable features
  • Cisco Secure Access Analytics analytic story using firewall telemetry
  • Expanded Windows threat detection analytics covering PowerShell abuse, process injection, privilege escalation, cloud/Azure activity, RMM tools, and C2 frameworks

Beta — feedback welcome: [email protected]