Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
M8seven/cve-2026-22874-gitea-ssrf-allowlist
CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.
diamorphine666/CVE-2026-23744-exploit
Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744) | language: Python
Cyber-note/CVE-2026-34835-Black-box-Analysis
A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and defensive recommendations. | topics: bug-bounty, cve, cve-2026-34835, cybersec...
sagsooz/PageBuilderCK-CVE-2026-56290-Exploit
Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter | language: Python
sgkdev/ptrace_may_dream
CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer | language: C
0xBlackash/CVE-2026-50656
CVE-2026-50656 | language: C++
striga-ai/CVE-2026-23918
Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE. | language: Python
0xCyberstan/CVE-2026-53360-POC
PoC for CVE-2026-53360: guest-triggered heap out-of-bounds read/write in KVM SEV-SNP Page State Change (PSC) handling. | language: C
Mkps/CVE-2026-38751-OpenSTAManager-Arbitrary-File-Upload-PoC
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an authenticated attacker to upload a malicious module via the module update functio...
0xCyberstan/CVE-2026-31694-POC
Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): a malicious FUSE server overflows a page-cache page by 24 bytes. PoC plus an unprivileged local-root exploit via /etc/passwd page-cache corruption. Ru...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
ffffffff0x/1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup | topics: blueteam, collection, ctf, hacking, ics-security, infosec, linux-learning, markdown-article, pentest, pentest-tool, poc, post-penet...
ffffffff0x/f8x
红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool | topics: bash, bash-script, ctf, ctf-tools, ffffffff0x, linux, pentest-tool, shell, vps | language: Shell | stars: 2156 | forks: 295 | updated 2026-08...
abc123info/BlueTeamTools
蓝队分析研判工具箱,功能包括内存马反编译分析、各种代码格式化、网空资产测绘功能、溯源辅助、解密冰蝎流量、解密哥斯拉流量、解密Shiro/CAS/Log4j2的攻击payload、IP/端口连接分析、各种编码/解码功能、蓝队分析常用网址、java反序列化数据包分析、Java类名搜索、Fofa搜索、Hunter搜索等。 | stars: 1853 | forks: 109 | updated 2026-08-14T01:42:00Z | p...
yuvikapoorDFIR/MailItemsAccessed-GUI
The Mail Items Accessed Correlator is a Windows DFIR tool that matches MailItemsAccessed events from Unified Audit Log exports with email metadata from Microsoft Purview Content Search, helping identify which emails a th...
zenmisael/Threat-Hunting
Host-Based EDR + Rootkit Detection + DFIR Tool (Single Binary) | language: Go | stars: 0 | forks: 0 | updated 2026-03-20T04:58:57Z | pushed 2026-03-20T04:58:54Z
vuln000/BlueTeamNote
蓝队笔记--------面向安全事件的实践指南,实战笔记。包含安全事件发现(威胁狩猎)、应急处置(应急响应)、安全数据挖掘、威胁情报等多个方面。 | topics: blueteam, notes, security, tutorial | stars: 22 | forks: 2 | updated 2026-08-08T20:05:56Z | pushed 2026-05-20T03:28:40Z
xyzwebmaster/All-in-One-Whitehat-Security-Tool
Real-time system security monitor with Windows toast notifications and first-run GUI setup. Tracks firmware integrity, drivers, network connections, processes, registry, and security events. Auto-starts on boot. | langua...
HARSHADBALAJI/python-security-toolkit
A suite of custom information security tools including packet sniffers, keyloggers, and pixel manipulators. | topics: cybersecurity, encryption, networking, python | language: Python | stars: 0 | forks: 0 | updated 2026-...
Kuldeep6474/file-integrity-monitor
cybersecurity python sha256 file-integrity hashing security-tools ethical-hacking infosec cryptography file-monitoring | topics: cryptography, cybersecurity, ethical-hacking, file-monitoring, fileintegrity, hashing, pyth...
sinXne0/pentest-mcp
Ethical penetration testing MCP server — 40+ security tools for Claude | language: Python | stars: 0 | forks: 0 | updated 2026-03-20T05:13:42Z | pushed 2026-03-20T05:13:39Z