Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
4minx/CVE-2026-32475
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE | language: Python
dinosn/cve-2026-32475-elementor-pro-lab
A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync) | language: Shell
goldendivider/cve-2026-6471-postgres-logical-decoding-dlopen
postgres CVE-2026-6471 Exploit | topics: exploit, exploitmatic, poc, postgresql | language: C
goldendivider/gpgsm-cve-2026-57062-cms-gcm-short-tag
gpgsm CVE-2026-57062 exploit POC | topics: exploit, exploitmatic, gpgsm
joaovicdev/EXPLOIT-CVE-2026-22778
language: Python
rmhowe425/POC-CVE-2026-7873
PoC exploit code for CVE-2026-7873 | language: Python
pvharmo2/gha-lab-4a8fad8536
Security-research lab reproducing CVE-2026-39382 (GHSA-5jxf-vmqr-5g82): command injection in dbt-labs reusable workflow open-issue-in-repo.yml, driven by a dbt-core-style docs-issue.yml caller | topics: academic-research...
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
AgentTrust 是面向 AI Agent 的运行时安全与评测控制面,在输入、外部上下文、工具执行前、工具结果和最终输出五个边界实施策略检查,并提供来源追踪、污点传播、MCP/A2A 防护、红队评测、人工审批、回滚和可复现发布证据。
创建者: wj-0623
AgentTrust 是面向 AI Agent 的运行时安全与评测控制面,在输入、外部上下文、工具执行前、工具结果和最终输出五个边界实施策略检查,并提供来源追踪、污点传播、MCP/A2A 防护、红队评测、人工审批、回滚和可复现发布证据。
Wraith — 网安专用 pi agent(自包含):红队人设 + 16 命令 + 10 工具 + 817 技能库,离线可用,为 Kali 打造
创建者: ViryaZheng
Wraith — 网安专用 pi agent(自包含):红队人设 + 16 命令 + 10 工具 + 817 技能库,离线可用,为 Kali 打造
本地运行的个人 OSINT 信息采集与分析工具。后端 FastAPI + SQLite,前端 Vue 3 + Vite + Element Plus,可采集 RSS、通用网页、政策公告、arXiv、B站 UP 动态等公开信息源,支持全文检索、实体关联、关键词预警、报告导出、每日简报、AI 分析、健康看板与错误日志。项目不内置绕过反爬或登录态的采集逻辑,需授权请求头的接口由用户自行填写。
创建者: nbrs666
本地运行的个人 OSINT 信息采集与分析工具。后端 FastAPI + SQLite,前端 Vue 3 + Vite + Element Plus,可采集 RSS、通用网页、政策公告、arXiv、B站 UP 动态等公开信息源,支持全文检索、实体关联、关键词预警、报告导出、每日简报、AI 分析、健康看板与错误日志。项目不内置绕过反爬或登录态的采集逻辑,需授权请求头的接口由用户自行填写。
Configured a virtualized subnet network in UTM that simulates a misconfigured enterprise network. Conducted active reconnaissance, brute force credential attacks, and unauthenticated remote code execution, MySQL privilege escalation and webshell injection. Then documented steps to take to harden the network.
创建者: JSUser05
Configured a virtualized subnet network in UTM that simulates a misconfigured enterprise network. Conducted active reconnaissance, brute force credential attacks, and unauthenticated remote code execution, ...
信息系统渗透智能化测试平台 — Qt5/C++ 前端重构
创建者: gaoyuann
信息系统渗透智能化测试平台 — Qt5/C++ 前端重构
Jingwei 是一套面向红队/紫队场景的**全生命周期自动化渗透测试平台**。以“模拟高级威胁组织攻击行为”为核心设计理念,覆盖从外部侦察到内网全域占领的完整攻击链路。
创建者: Domren
Jingwei 是一套面向红队/紫队场景的**全生命周期自动化渗透测试平台**。以“模拟高级威胁组织攻击行为”为核心设计理念,覆盖从外部侦察到内网全域占领的完整攻击链路。
🛡️
创建者: laserduor
suchenhua/logisme-debate-coach
开源华语辩论 AI 教练知识库:覆盖备赛 / 复盘 / 评判全链路。含 17 篇方法论(攻防分级·逐帧纠偏·话术交付)、3 个核心 Skill、24 位辩手风格卡与模板库。部分内容基于精靈Moon《辩论筑基》与 grill-me 开源改编,CC BY-NC-SA 4.0 许可。 | language: Python | stars: 2 | forks: 0 | updated 2026-09-13T12:27:11Z | pushed...
Yunkun-Ley/AI-Network-Security-Learning
AI网络攻防全栈学习项目 - 涵盖对抗样本、模型防御、安全评估、渗透测试等内容 | stars: 0 | forks: 0 | updated 2026-09-04T08:46:55Z | pushed 2026-09-04T08:46:53Z
monetgames/TankBase
坦克基地 Tank Base - 融合 RPG、塔防与 Roguelite 元素的俯视角坦克攻防游戏 | stars: 0 | forks: 0 | updated 2026-09-05T15:35:19Z | pushed 2026-09-12T14:41:18Z | homepage: https://monetgames.github.io/TankBase/