03 Aug 2026
Zsh Codex is a ZSH plugin that provides AI-powered code completion directly in the command line, utilizing OpenAI's Codex and Google's Generative AI (Gemini) technologies. It allows users to input comments or variable names, which the AI then translates into corresponding code snippets, enhancing productivity and workflow efficiency. Notable features include support for multiple AI services, configurable service options, and easy integration with existing ZSH setups.
03 Aug 2026
Ultralytics YOLOv5 is a high-performance computer vision model designed for tasks such as object detection, image segmentation, and image classification. Built on the PyTorch framework, it combines speed and accuracy, leveraging extensive research to deliver optimal results while maintaining user-friendliness. Notable features include support for multiple tasks, detailed documentation, and a collaborative community platform for user support.
03 Aug 2026
YAPF is a Python code formatter that automatically reformats source code to conform to a specified style guide, utilizing an algorithm similar to `clang-format`. Its primary use case is to streamline code formatting, making it easier for developers to maintain consistent styles across their projects. Notable features include support for various formatting styles, recursive file processing, and integration with multiple text editors through plugins.
03 Aug 2026
XSS-LOADER is a comprehensive tool designed for generating and scanning XSS (Cross-Site Scripting) payloads, as well as finding vulnerable websites using XSS dorks. It features a user-friendly interface that allows customization of payloads across various HTML tags, encoding options, and pre-defined payload types to facilitate effective XSS attacks and testing. Notable capabilities include an extensive library of payload forms, encoding mechanisms, and automated scanning for XSS vulnerabilities in web applications.
03 Aug 2026
WPGarlic is a proof-of-concept fuzzing tool designed to identify vulnerabilities in WordPress plugins, having discovered over 300 vulnerabilities across nearly 30 million sites. It employs specialized techniques for fuzzing plugin functionality, producing detailed reports that may contain false positives, necessitating further analysis to confirm genuine vulnerabilities. Notable features include customizable payloads for targeted testing and a focus on lesser-known plugins to uncover potential security risks that may have been overlooked.
03 Aug 2026
Wfuzz is a versatile web application fuzzer designed to facilitate security assessments by allowing users to inject payloads into HTTP requests, thus enabling complex vulnerability testing across various web components, such as parameters and headers. Notable features include a modular plugin architecture for easy extension, a simple interface for the integration of previous HTTP interactions, and the ability to both identify and exploit web vulnerabilities efficiently. This tool is specifically tailored for penetration testers looking to enhance their web application security evaluation capabilities.
03 Aug 2026
Valid8Proxy is an efficient tool for fetching, validating, and storing various types of proxies including HTTP, HTTPS, SOCKS4, and SOCKS5. It is primarily used for web scraping, OSINT, automation, and network testing, featuring high-speed concurrent validation, customizable options for timeout and thread count, and the ability to save valid proxies to a file. The tool supports multiple live sources for proxy fetching and allows for direct validation of user-provided proxy lists.
03 Aug 2026
UPnP-Hack is a security research tool designed to exploit vulnerabilities in Universal Plug and Play (UPnP) protocols used in wireless access points and routers. Its primary use case is to identify and demonstrate potential attack vectors that attackers may exploit due to poor implementation of security measures, particularly focusing on WEP and WPA/WPA2 vulnerabilities. Notable features include detailed analysis of security flaws, example exploits, and a framework for understanding the layered architecture of wireless connectivity devices.
03 Aug 2026
unve1ler is a social engineering tool designed to reveal digital footprints and visual clues on the internet by locating online profiles associated with usernames and offering reverse image search capabilities. It conducts searches across multiple platforms for user profiles while providing users a comprehensive summary of their findings, including execution time and errors. Notable features include efficient multi-threading for expedited reconnaissance and support for reverse image searches across major search engines.
03 Aug 2026
Tinfoil-Chat is a simple chat application that implements 2048-bit RSA encryption, designed primarily for educational purposes in learning encryption, GUI development, and networking concepts. Notable features include a user verification process to mitigate man-in-the-middle attacks and the utilization of randomly generated usernames and RSA keys for enhanced anonymity. However, the tool comes with significant security vulnerabilities, such as susceptibility to attacks due to the use of the pickle library and flaws in the RSA key management.
03 Aug 2026
ThunderCloud is a cloud exploit framework designed for penetration testing of AWS and Azure environments. It features modules for enumerating roles, extracting credentials from vulnerable Cognito endpoints, attacking S3 buckets, and phishing AWS SSO credentials. This tool facilitates various attacks, making it valuable for security professionals assessing cloud infrastructure vulnerabilities.
03 Aug 2026
TEx is a Telegram exploration tool designed for researchers, investigators, and law enforcement to efficiently collect and process large volumes of data from Telegram groups associated with criminal activity, fraud, and security issues. Its key features include a connection manager, group and user information scrapping, advanced message listening and reporting capabilities, multimedia downloading with custom settings, and integration with Elastic Search and Discord for notifications. Additionally, TEx supports HTML report generation and image OCR using Tesseract, making it a comprehensive solution for data analysis in Telegram environments.
03 Aug 2026
The tool "teams_dump" is a proof of concept for extracting and decrypting cookies from the latest version of Microsoft Teams. Its primary use case is to enable users to list and dump cookie data from the Teams database into a JSON file, facilitating access to stored cookie information. Notable features include a Python script for direct extraction and a bundled executable version, simplifying the extraction process for users.
03 Aug 2026
TalkingHeads is a Python library that facilitates seamless communication with multiple chat agents, including ChatGPT, Claude, Copilot, and others, through browser automation. Its primary use case is to enhance workflows by enabling users to interact with multiple AI models and agents simultaneously via a simplified interface. Notable features include support for custom interactions, multi-agent functionality, conversation logging in various formats, and options for model switching, making it a versatile tool for automating AI chat interactions.
03 Aug 2026
SysReptor is a customizable pentest reporting platform that streamlines the creation of penetration test reports for security professionals. It offers features such as HTML report design, Markdown writing support, PDF rendering, and options for self-hosting or cloud deployment, making it an efficient tool for enhancing the reporting process in cybersecurity assessments.
03 Aug 2026
SWIRL is an open-source federated AI search tool designed to query applications in real time without the need for data duplication or the establishment of a vector database. It allows users to pose questions and receive ranked results along with clickable sources, thereby streamlining search processes across multiple data sources while enforcing original permissions. Key features include ease of deployment via Docker, compatibility with numerous connectors, and the capability to generate answers using a chosen large language model (LLM).
03 Aug 2026
Stitch is a cross-platform Python-based Remote Administration Tool designed for educational and research purposes, enabling users to create customizable payloads for Windows, Mac OSX, and Linux environments. It incorporates features such as command auto-completion, keylogging, file manipulation, and system monitoring, while ensuring secure communication through AES encryption. The tool also facilitates the creation of installers for payload deployment and supports various functionalities specific to each operating system, such as webcam access and password dumping.
03 Aug 2026
The "start-here-guidelines" repository serves as a community-driven platform for students to gain practical experience in collaborative software development. It guides users through the process of forking and contributing to various projects while emphasizing teamwork, conflict resolution in Git, and providing a structured pathway to involvement in coding initiatives. Notable features include clear instructions for using Git commands, maintaining repository synchronization, and fostering an environment where iterative learning through failure is encouraged.
03 Aug 2026
The Stable Diffusion web UI provides an interactive interface for utilizing the Stable Diffusion model, tailored for generating images from text prompts. Key features include support for original txt2img and img2img modes, advanced image manipulation options like outpainting and inpainting, and tools for enhancing image quality, such as GFPGAN and RealESRGAN. The interface also allows for customizable prompts, batch processing, and access to external community scripts, making it a versatile tool for users interested in image synthesis.
03 Aug 2026
ssh-audit is a comprehensive auditing tool for SSH servers that evaluates security configurations and algorithms used in SSH1 and SSH2 protocols. Key features include the ability to gather information about key-exchange, host-key, and encryption algorithms, alongside offering recommendations and security insights based on recognized software versions. With no dependencies and compatibility with multiple Python versions, the tool facilitates detailed analysis while retaining ease of use through various command-line options.
03 Aug 2026
SploitScan is a comprehensive tool designed for cybersecurity professionals to efficiently identify exploits related to known vulnerabilities and assess their likelihood of exploitation. Key features include integration with the Exploit Prediction Scoring System (EPSS), a patching priority system based on vulnerability metrics, and the ability to import results from various vulnerability scanners. The tool also provides AI-powered risk assessments, supports multiple CVE handling with export options, and offers a user-friendly interface for streamlined operations.
03 Aug 2026
SourceWolf is a web crawling and endpoint discovery tool designed to efficiently identify hidden endpoints and extract relevant information from web sources. Its primary use case includes crawling through responses for hidden endpoints, extracting JavaScript variables, and enumerating social media links, all while utilizing session management for improved speed. Notable features include local response file crawling, status code retrieval for URL lists, and support for brute-forcing hostnames with customizable threading options.
03 Aug 2026
Python
★ 1825
socialscan is a high-performance tool designed for accurate checks of email address and username availability across various online platforms. Utilizing asynchronous querying methods via asyncio and aiohttp, it ensures 100% accuracy while executing bulk queries rapidly, making it suitable for both individual and large-scale checks. The tool supports both email and username queries, can be utilized through a command-line interface or as a Python library, and includes a wide range of platforms for comprehensive user availability assessments.
03 Aug 2026
Social Mapper is an open-source intelligence tool designed for large-scale correlation of social media profiles using facial recognition technology. Primarily aimed at penetration testers and red teamers, it facilitates automated gathering of target profiles across multiple platforms, including LinkedIn, Facebook, and Instagram, enabling efficient data analysis for social engineering attacks. Notable features include support for various input types, reporting capabilities, and the ability to minimize false positives during searches.
03 Aug 2026
Smuggler is an HTTP Request Smuggling and Desync testing tool developed in Python 3, designed to identify potential vulnerabilities in web applications that may lead to HTTP request smuggling attacks. Its notable features include support for various HTTP methods, the ability to process both single URLs and lists of hosts, customizable logging, and configurable request mutations to enhance testing accuracy. Users must be aware that the tool may produce false positives and negatives, and it integrates configuration files for tailored payload definitions.