Web appOpen in Telegram
RRoot Access Club

Root Access Club

@RootAccessClub · channel · indexed since 2026-05-19
272subscribers−1 in a week
152average post reach
55.9%ER — reach to subscribers
20posts in 30 days
R
Root Access Club
Photo
click to show
PDF Exploit Defense Toolkit 🛡 Two clean, pure-Python tools for handling malicious PDFs: 1️⃣PDF Exploit Scanner Detects high risk indicators (OpenAction, JS, Launch, XFA, heap sprays…) 🤔 ➡️ Structural patcher + full image based sanitizer included GitHub 😨 2️⃣ IP Scanner for Exploited PDFs Pulls hidden IPs/ranges from hijacked PDFs (byte-level) 🤔 ➡️ Scans common ports + temporary firewall to block them GitHub 😨 🛩 @RootAccessClub
5 · 216 ·
R
Root Access Club
Photo
click to show
numasec – The open source AI security agent 🧠 numasec is an AI security agent that runs in your terminal ⚪️ It uses the tools already installed on your machine, follows security runbooks, switches between cyber agents, keeps the operation context alive, tracks findings, stores evidence and helps turn the work into reports 🤖 GitHub 🐱 💎 @RootAccessClub
7 · 265 ·
R
Root Access Club
Photo
click to show
AutoCVE – One Click CVE Discovery: Select Projects, Audit Source Code, Verify Vulnerabilities, Generate Reports, Fully Automated 💥 GitHub 😀 📱 @RootAccessClub
4 · 249 ·
R
Root Access Club
Photo
click to show
PentestCode 💥 AI penetration testing agent in your terminal Multi-agent architecture Engagement state tracking , 20+ LLM providers ✨ GitHub 🔗 💎 @RootAccessClub
9 · 231 ·
R
Root Access Club
How I Found 7 XSS Using a Custom Nuclei Template 🔬 Read Here 📖 #CyberSecurity #BugBounty #xss ⚡️@RootAccessClub
5 · 197 ·
R
Root Access Club
Photo
click to show
DarkTortilla RAT – Telegram Exfiltration & Payload Extraction ☢ GitHub 🔗 #Payload #CyberSecurity 🪎 @RootAccessClub
8 · 170 ·
R
Root Access Club
Photo
click to show
BugScanner 🩻 Automated web security reconnaissance & vulnerability assessment tool for bug bounty hunters. Discover attack surfaces, fingerprint technologies, detect common web vulnerabilities, and generate actionable security reports 📋 GitHub 🎖@RootAccessClub
9 · 177 ·
R
Root Access Club
Photo
click to show
🦠 Stuxnet A new GitHub project provides an educational reconstruction of the infamous Stuxnet worm, based on years of reverse engineering research into the original 2010 samples 🔬 The project explores components such as rootkits, privilege escalation, Step7/S7 hooks, propagation mechanisms, and PLC-related functionality ⚙️💻 🧪 Intended for malware analysis, security research, and academic study GitHub 🔗 💎 @RootAccessClub
7 · 201 ·
Root Access Club
PSAITO – New PS5 WebKit Research ToolExperimental toolkit for PS5 🫯 firmware 9.00 – 13.60 ✅ Browser only exploit that gives memory read/write + syscall primitives inside the WebKit process ✨ Research only ⚠️ GitHub 🔗 🥇@RootAccessClub
4 · 155 ·
R
Photo
click to show
knife – A reverse engineer's toolkit in Rust 🔪 Parse, triage, disassemble, and audit PE, ELF, and Mach-O from one small binary. Static only: it reads the bytes on disk and never runs the target 🎯 GitHub 🌐 © @RootAccessClub
7 · 163 ·
R
Root Access Club
Photo
click to show
Claude Red 🌪 Offensive security skills for Claude a collection of "SKILL.md" files designed to turn Claude into a more context aware red team assistant Covers areas like web security, AD, cloud, recon, exploit development, EDR evasion, and more ⭐️ GitHub 🔗 🛡️@RootAccessClub
14 · 178 ·
R
Root Access Club
Photo
click to show
XSS Labs🔬 An intentionally vulnerable lab environment for practicing XSS across different contexts, including Reflected, Stored, DOM-based, and JavaScript based XSS A practical resource for learning how XSS works and how to mitigate it 🕷️ Github 🧪 ⚡️ @RootAccessClub
8 · 148 ·
R
Root Access Club
Photo
click to show
CVE-2026-12793 – JetFormBuilder WordPress Plugin 🆘 Critical vulnerability (CVSS 9.8) ⚠️ Affects versions ≤ 3.6.2 Unauthenticated privilege escalation Fixed in version 3.6.2.1 and later ✅ Attack Flow : 1⃣ Detect JetFormBuilder + version ≤ 3.6.2 (readme.txt) 2⃣ Discover form ID from public pages (data-form-id, /register/, etc.) 4⃣ POST to referer page with ?jet_form_builder_submit=submit&method=ajax 4⃣ Register User action runs → new WP user created If you're using this plugin, update immediately ‼️ GitHub ⛓‍💥 @RootAccessClub
2 · 157 ·
R
Root Access Club
Photo
click to show
OWASP Amass 🔎 An open source framework for network mapping and attack surface discovery • Subdomain & DNS enumeration • OSINT-based asset discovery • Infrastructure mapping • External attack surface analysis Built by OWASP, Amass is a solid reconnaissance tool for security researchers and bug bounty hunters ⭐️ GitHub 🔗 💎 @RootAccessClub
4 · 155 ·
R
Root Access Club
Photo
click to show
Legion — Automated Network Pentesting 🛡️ Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery 🔸 Nmap, Nikto, WhatWeb, Hydra, SMBenum 🔹 CVE & vulnerability mapping 🔸 Automated scanning & enumeration Github 🔗 📡 @RootAccessClub
7 · 163 ·
R
Root Access Club
Photo
click to show
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain 💥 Unauthenticated Arbitrary File Read → Admin Token Forge → Sandbox Bypass → RCE 🌪 CVSS : 10.0 + 9.9 (Critical) ⚠️ Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) ✅ Github 🌐 🪎 @RootAccessClub
4 · 150 ·
R
Root Access Club
Photo
click to show
Osintgram 👥 An open source OSINT framework for Instagram reconnaissance and information gathering 🔎 Key Features: • Profile & content analysis • Followers / Following analysis • Hashtag & location searches • Media and metadata analysis • Account comparison • Interactive Web UI • AI assisted mode with local Ollama support • JSON & HTML report generation GitHub 🔗 ⚠️ Use responsibly and only with data you are authorized to investigate 💎 @RootAccessClub
5 · 158 ·
R
Root Access Club
Photo
click to show
WordPress Critical RCE 🚨 CVE-2026-87902 | CVSS 9.2 🫯 A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution 💣 Affected versions span 4.7 → 7.1.1 🦠 🛡️ Fix: Update to the latest patched WordPress release for your branch GitHub 🔗 @RootAccessClub
7 · 159 ·
ReplyWordPress Critical RCE 🚨 CVE-2026-87902 | CVSS 9.2 🫯 A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution 💣 Affected versions span 4.7 → 7.1.1 🦠 🛡️ Fix: Update to the latest
CVE-2026-87902 🪤 PoC for CVE-2026-87902 – unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab GitHub 🔗 ⚠️ Authorized security testing, education, and defensive research only 💎 @RootAccessClub
1 · 147 ·
R
Root Access Club
Photo
click to show
Prompt Injection in the Wild 💉 A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems Link 🔗 @RootAccessClub
6 · 148 ·
R
Root Access Club
Photo
click to show
AutoPWN Suite ⚡️ An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing ✨ • Nmap-based network & service enumeration • CVE & vulnerability discovery • Automated exploit searching • Web vulnerability testing • Directory enumeration • Web UI + REST API • Scan scheduling & automation • Email / Webhook notifications • Optional evasion techniques GitHub 🔗 🌪 @RootAccessClub
8 · 118 ·
R
Root Access Club
Photo
click to show
Relapse – PS5 Jailbreak Exploit 🎮 A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 🎯 🔹 WebKit Exploit 🔹 Kernel Exploit 🔹 Execution of unofficial payloads 🔹 Support for payloads such as kstuff and etaHEN When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 💥 ⚠️ Check your console's firmware version before attempting anything GitHub 🔗 🪎 @RootAccessCLUB
6 · 101 ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count