Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
abdugafforov-bobur/CVE-2026-54415-PoC
PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover | language: Python
b0ySie7e/OpenSTAManager-RCE-Exploit-CVE-2026-38751
OpenSTAManager-RCE-Exploit-CVE-2026-38751 | language: Rust
KVM: x86: Fix shadow paging use-after-free due to unexpected role
ipv6: account for fraggap on the paged allocation path
af_unix: Set gc_in_progress to true in unix_gc().
biosGit/CVE-2026-9090
Casdoor version 2.362.0 | language: Python
F2u0a0d3/CVE-2026-42945-nginx-rift-poc
PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab, empirical address discovery, OOB-verified offset sweep. Original disclo...
shinthink/CVE-2026-57517
💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell | topics: blind-sqli, control-web-panel, cve-2026-57517, cwp, exploit, pentesting, python, rce, s...
diamorphine666/CVE-2026-33017-Exploit
Unauthenticated RCE in Langflow <1.9.0 (CVE-2026-33017) Exploit | language: Python
M8seven/cve-2026-22874-gitea-ssrf-allowlist
CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
weishen250/npscrack
蓝队利器、溯源反制、NPS 漏洞利用、NPS exp、NPS poc、Burp插件、一键利用 | language: Java | stars: 706 | forks: 71 | updated 2026-08-06T11:17:42Z | pushed 2025-04-26T11:51:31Z
RoomaSec/RmTools
蓝队应急工具 | language: YARA | stars: 545 | forks: 51 | updated 2026-07-27T11:59:08Z | pushed 2024-06-10T08:44:04Z
Am1azi3ng/WinTracePro
蓝队工具,一款小白都能用的Windows溯源Tools,支持AI一键分析 | stars: 70 | forks: 4 | updated 2026-08-06T11:22:09Z | pushed 2026-07-14T02:09:11Z
xiao-xian-ok/TingLan
一款基于流式处理架构的蓝队流量分析工具,集成Webshell检测、OWASP攻击识别、自动解码和隐写分析能力的工具/Stream-based Blue Team traffic analyzer with integrated Webshell detection, OWASP attack identification, auto-decoding, and steganography analysis. | language: Py...
Fausto-404/EFF-Monitoring
EFF-Monitoring(Efficient Monitoring,高效监控),是一款面向安全运营 / 蓝队的本地告警处理工具,聚焦“高效日志处理 + 自动化情报补全 + AI 研判”,帮助安全监测人员在攻防演练和日常值班中快速看懂告警、打通上下游。 | topics: monitoring-tool, security-operations | language: Python | stars: 20 | forks: 2 | u...
burpheart/mbtm
攻击流量模拟 用于迷惑蓝队 分散蓝队精力 混淆真实攻击流量 | language: Python | stars: 196 | forks: 21 | updated 2026-03-12T03:05:02Z | pushed 2021-02-25T12:03:08Z
Blue-Team-CN/Attack-traffic-PACPs
攻击流量包,辅助安全运营/分析人员,HVV蓝队工程师开展流量攻击研判工作 | stars: 72 | forks: 12 | updated 2026-07-30T19:10:00Z | pushed 2023-09-07T08:59:28Z
satan1a/awesome-cybersecurity-blueteam-cn
网络安全 · 攻防对抗 · 蓝队清单,中文版 | topics: attack-defense, awesome, blue-team, chinese-translation, cybersecurity | language: HTML | stars: 967 | forks: 120 | updated 2026-08-11T02:46:49Z | pushed 2023-12-03T15:29:38Z | homepage: ...
ChinaRan0/BlueTeamTools
蓝队工具箱 | language: Python | stars: 560 | forks: 29 | updated 2026-08-13T06:38:56Z | pushed 2025-06-22T05:53:07Z
CuriousLearnerDev/TrafficEye
This tool is designed to help penetration testers and network administrators identify potential security threats, especially those targeting web applications such as SQL injection, XSS, and WebShells. Its modular desig 该...