This GitHub Organization contains code repositories linked to Kudelski Security research papers, blog-posts, POCs or talks. These projects are usually not maintained in the long run so they are not intended to be used in production unless explicitly mentioned in the repository itself. All software is provided as-is.
Kudelski Security takes the security of our software products and services seriously.
If you believe you have found a security vulnerability in any Kudelski Security-owned repository, please report it to us as described below.
Please do not report security vulnerabilities through public GitHub issues. Also do not report security vulnerabilities for archived repositories. Archived repositories are not maintained in any way and are left purely for research purposes only. They should not be used in production projects. This disclaimer is clearly stated on each of these archived projects to avoid any confusion.
To report vulnerabilities on non-archived projects, please visit https://vdp.kudelski.com/ and provide the appropriate vulnerability details.
We prefer all communications to be in English.
The Kudelski Security Disclosure Policy can be found on the VDP page. You can view it by visiting https://vdp.kudelski.com/p/Policy