Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
oscerd/CVE-2026-40858
Reproducer for CVE-2026-40858 — Apache Camel camel-infinispan remote aggregation repository unsafe deserialization (RCE) | topics: apache-camel, cve, proof-of-concept, security, vulnerability | language: Java
bugresearch/CVE-2026-50980
oPanel DNS-Based Cross-Site Scripting (XSS) & Session Hijacking | language: Python
bugresearch/CVE-2026-50979
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component | language: Python
L4V4D0/CVE-2026-29519-Lucee-Reflected-XSS
Proof of Concept for Reflected XSS in Lucee CFML (CVE-2026-29519)
inforcqb/CVE-2026-43499-pja110
language: C
aexdyhaxor/CVE-2026-46331
A Proof of Concept (PoC) exploit for CVE-2026-46331 | language: C
BiiTts/CVE-2026-56423-MISP-deleteSelection-BrokenAccessControl
PoC for CVE-2026-56423: MISP deleteSelection broken access control (CWE-862, contributor hard-deletes other orgs' Event Reports/Sharing Groups, CVSS 8.8) | topics: broken-access-control, cve, cve-2026-56423, cwe-862, ido...
phil-dirt/CVE-2026-41089-LongLogon
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overfl...
pubglite55/oppo-ghostlock
OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation | language: C
BiiTts/CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass
PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1) | topics: apache-apisix, api-gateway, apisix, authentication-bypass, cve, cve-2026-49230, jwe, p...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
melomac/fashion
Compute and match file digests for threat hunting and binary analysis. | language: Swift | stars: 1 | forks: 0 | updated 2026-03-21T16:22:21Z | pushed 2026-03-21T16:30:42Z
adiccc/ThreatHuntingEngine
stars: 0 | forks: 0 | updated 2026-03-21T16:53:14Z | pushed 2026-03-21T16:53:11Z
sunilnaidu265/Threat-Hunting
stars: 0 | forks: 0 | updated 2026-03-21T20:51:17Z | pushed 2026-03-21T20:51:14Z
julieagnessparks/saas-hunt-guides
A repo to track some threat hunting guides and logging visibility details for critical SaaS applications. | stars: 2 | forks: 0 | updated 2026-03-21T22:43:29Z | pushed 2026-03-21T21:07:05Z
ArronJablonowski/birtha
Bash Incident Response & Threat Hunting Automation | language: Shell | stars: 0 | forks: 0 | updated 2026-03-22T00:05:35Z | pushed 2026-03-22T00:05:31Z
fukusuket/THuntCloud
🪽Docker Compose–based AWS CloudTrail threat hunting tool. Ingests logs into DuckDB with Rust, and lets you query them in natural language via an AI-powered Streamlit UI — no SIEM, no cloud dependency.🪽 | topics: aws, clo...
ValorAssistAI/Threat-Hunter
Threat Hunting, malware analysis, IoC Tracking, Vulnerability Analysis | language: TypeScript | stars: 0 | forks: 0 | updated 2026-03-22T11:40:38Z | pushed 2026-03-22T11:40:33Z
Yamato-Security/hayabusa
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs. | topics: attack, cybersecurity, detection, dfir, event, forensics, hayabusa, hunting, incident, incident-respons...
dilkhaz12/llama3.1-8B-threat-hunting
LLAMA3.1 8B-based Threat Hunting Framework with GRPO | language: Python | stars: 0 | forks: 0 | updated 2026-03-22T12:51:52Z | pushed 2026-03-22T12:51:48Z
Bhavya2-4/Threat-hunting-Reports
stars: 0 | forks: 0 | updated 2026-03-22T13:02:41Z | pushed 2026-03-22T13:02:38Z