Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
eyesecurity/wp2shell-compromise-scanner-plugin
Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137) | language: PHP
ZenithGenius/wordpress-batch-rce-lab
CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab. | language: HTML
0xBlackash/CVE-2026-63030
CVE-2026-63030 | language: Python
ananay/wp2shell-lab
Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain | language: PHP
skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
The wp2shell vulnerability chain represents one of the most significant WordPress Core security issues in recent years. Because exploitation begins with an unauthenticated request and can ultimately result in Remote Code...
Lukols-Dev/wp-cve-2026-63030-check
Non-intrusive exposure checker for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 / CVE-2026-60137). | language: Python
tcyph3r/wp2shell-cve-2026-63030-root-cause
language: Python
0xgh057r3c0n/CVE-2026-0740
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload | language: Python
sentinel-aidefense/CVE-2026-56164-EXP
CVE-2026-56164 EOP Exploit
JohenLastGen-JLG/wp2shell
wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137) | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
jenn619/frida_Hook_tools_Android
基于 [Frida](https://frida.re/) 的 Android 应用安全分析工具集,运行时自动捕获加密/哈希参数,监控网络请求、WebView、动态加载等行为,并内置 Root/模拟器检测绕过。该项目适合渗透测试人员,遇到加了挺牛b的壳的app绕不过也正常,倘若目标app把类名做了混淆,可以把混淆后的类名与脚本中的类名做替换 | language: JavaScript | stars: 8 | forks: 0 | u...
opsqw/scoop-security
Scoop bucket for Penetration Testing and Cybersecurity related tools. 用于渗透测试和网络安全相关工具下载、安装和自动更新的Scoop软件仓库。 | topics: cybersecurity, cybersecurity-tools, pentesting, pentesting-tools, scoop, scoop-bucket, security, securi...
Hmx-7488/testing-security
面向后端的一站式安全审计 Skill:从风险分析到 P0 功能测试、一键回归、八维攻防渗透、漏洞报告。不算返回码,只验计算结果对不对。 | stars: 0 | forks: 0 | updated 2026-07-20T09:05:56Z | pushed 2026-07-07T02:59:29Z
ok-helloworld/vibe-pentest
Vibe Pentest(AI 渗透测试)是一款基于 AI Agent 架构的自动化渗透测试工具,采用多 Agent 并行执行架构,能够对 Web 应用、API、管理后台等进行全面的黑盒渗透测试(包括业务逻辑漏洞评估),输出稳定可靠的安全报告,并提供可落地的整改建议。 | topics: ai-pentest, vibe-pentest | language: Python | stars: 205 | forks: 22 | upda...
zhaoxuya520/reverse-skill
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, ...
cha0upup/LeoAI
AI 驱动的后渗透综合管理平台,深度集成 LLM Agent,开箱即用。 | language: Java | stars: 279 | forks: 32 | updated 2026-08-12T13:44:50Z | pushed 2026-08-12T10:40:09Z
Unclecheng-li/VulnClaw
基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。 | topics: ai, ai-agent, ai-tools, ctf, cybersecurity, openclaw, penetration-testing, penetration-testing-tools, security-tools, s...
LvShenlyl/ti-auto-triage-lab
蓝队自动化威胁研判工具 — Blue Team Automated Triage Tool | language: Python | stars: 0 | forks: 1 | updated 2026-06-14T02:55:48Z | pushed 2026-06-13T09:12:07Z
hejiaying50-commits/blue-team-hw-simulation
项目模拟蓝队在护网值守场景中的工作流,覆盖以下环节: Web 访问日志采集与模拟生成 访问日志结构化解析 SQL 注入、XSS、文件上传、目录扫描、弱口令爆破、高频扫描等规则识别 告警风险评级与是否上报建议 攻击汇总表与事件研判报告输出 蓝队值守仪表盘展示与单条事件详情查看 | language: Python | stars: 1 | forks: 0 | updated 2026-07-19T11:51:03Z | pushed 2...
A4n9g7e2l/Xway
🛡️ 蓝队应急响应 / Linux 失陷主机一键排查。纯 Bash 单文件,零依赖,45 个检查模块 + 7 类隧道检测 + 6 类暴力破解 + 攻击路径时间线 + JSON-lines 日志 + 风险评分 + 横向移动证据链。集成 NOP Team 手册 v2.0.2 + 9 本公开应急手册 gap 分析(MIT)。 | topics: bash, blue-team, compromise-assessment, digital-f...