Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
VeronnX666/CVE-2026-3891
This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out. | language: Python
0xh7ml/CVE-2026-63030
language: Python
CerberusMrXi/Langflow-cve-2026-33017-exploit
CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated testing. Validates critical RCE vulnerability impact. For authorized security ...
Raimu0x19/CVE-2026-13001
language: Python
SY115/CVE-Writeups
Security vulnerability research writeups. CVE-2026-50402: Windows NTFS Elevation of Privilege (CVSS 7.8)
shinthink/CVE-2026-3891
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8 | topics: 0day, cve, exploit, file-upload, pentest, security, vulnerability, woocommerce, wordpress | language: Python
zi3lak/wp2shell_scanner
Non-intrusive detection scanner for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 + CVE-2026-60137). Detection-only, no exploitation. | language: Python
c0gnit00/Wp2Shell
Exploit POC for Wp2Shell, CVE-2026-63030 + CVE-2026-63137 | language: Python
r00tali/CVE-2026-39200
The value of the produk request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload xbnw0"><script>alert(1)</script>skc2h was submitted in the produk p...
Jvr2022/CVE-2026-46420
PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution. | topics: command-injection, cve-2026-46420, cwe-78, github-actions, poc, security-research, setup-php
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
hejiaying50-commits/Blue-Team-SOC-Alert-Triage
A local blue-team SOC alert triage and web attack incident response project built with Python, pandas, Streamlit, and Suricata-style logs.基于 Python 的蓝队 SOC 告警研判与 Web 攻击日志应急响应平台,支持多源日志解析、规则检测、风险评分、事件聚合与安全态势展示。 | language:...
ClinininSec/BlueTeamSkill
面向蓝队人员的 Claude Code Skill — 把 SIEM 分诊、日志审计、pcap 流量分析、应急响应、授权 SSH 远程采集五件事合并成一个「Coding Agent 副驾驶」。 | topics: blue-team, cybersecurity, hvv, security | language: Python | stars: 5 | forks: 1 | updated 2026-07-30T03:42:18Z |...
Hackerchen716/blueteam-log-analyzer
蓝队应急响应日志分析工具 | language: Python | stars: 13 | forks: 1 | updated 2026-08-05T05:34:40Z | pushed 2026-06-20T18:29:17Z
teishahbc/china-as-ips
language: Python | stars: 1 | forks: 0 | updated 2026-08-11T02:20:43Z | pushed 2026-08-11T02:20:39Z
Dainsleif233/awesome-Cloudflare-IPs
language: Python | stars: 0 | forks: 0 | updated 2026-08-11T11:50:51Z | pushed 2026-08-11T12:00:19Z
shangdi-w/proxy-tool
一键抓取公网sock,httpip,可以实现轮换出口IP,固定出口IP,供红队,渗透测试使用。防止在测试时,IP被封 | language: Lua | stars: 0 | forks: 0 | updated 2026-05-23T06:24:55Z | pushed 2026-05-23T06:24:51Z
nexorin9/qc-rule-red-team
基于 Z3 约束求解器的医疗质控规则红队工具,自动生成边界病例测试规则覆盖度,输出漏洞报告与可视化图表,支持多格式规则导入。 | language: Python | stars: 0 | forks: 0 | updated 2026-05-23T15:42:29Z | pushed 2026-05-23T15:42:13Z
0x7556/hackvideo
Hack视频教程:红队渗透测试、金刚狼WolfShell、工具使用教程 | stars: 0 | forks: 0 | updated 2026-05-24T09:00:16Z | pushed 2026-05-24T09:00:12Z
dreamaeiou/BlackRelay
BlackRelay 是一个面向红队场景的 AI API 中转与审计工具。它位于 AI 客户端与上游模型 API 之间,负责转发请求、记录 Prompt 和工具行为、按规则扫描敏感信息,并在 Claude 风格的流式响应中注入额外工具调用。 | language: Go | stars: 1 | forks: 0 | updated 2026-05-30T11:18:25Z | pushed 2026-05-30T11:17:29Z
ctfd3219/StarS
StarS 一站式企业信息测绘与供应链风险探测工具,深度优化红队攻防作业链路,自动化替代人工重复工作,极速排查各类安全漏洞。 | topics: config, github-config | language: Go | stars: 1 | forks: 0 | updated 2026-05-31T05:45:26Z | pushed 2026-05-26T09:16:20Z | homepage: https://github....