~/en/research $ ls -l ./lab
AI agents rebuilding real CVEs
Already disclosed and patched CVEs, reproduced by AI agents on stock images in a network with no internet egress. For every run I publish the PoC, the patch verification, the detection rules and where the agent fell short.
004
GitLab CE/EE
unauthenticated file read in the commits API
003
PaperCut NG/MF
from an authentication bypass to loading any class you name
002
Gitea diffpatch
code execution from an account without administrator privileges
001
Zimbra
command injection in the zimbra-snmp SNMP notification
RGS · Report Generative Security Tool
Audit reports written by an LLM that runs on your own machine.
iPhish Agent
Authorized phishing simulations with an agent that never leaves the local machine.
WP2Shell Checker
WordPress version read against CVE-2026-60137 and CVE-2026-63030.
Pentest-MCP
Pentesting tools exposed to an LLM over MCP and REST, each one in its own container.
Spectra Project
The 2024 work that opened the path: an LLM making attack decisions in simulation.
you@nullsector:~$ mail miguel
Collaborations, talks, press or research: write to me.
Need a pentest or a vulnerability assessment? Request it at Xpectra.ai ↗