Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
HORKimhab/CVE-2026-3300
CVE-2026-3300 | language: Python | homepage: https://www.wordfence.com/blog/2026/06/attackers-actively-exploiting-critical-vulnerability-in-everest-forms-pro-plugin/
stealth-engine/resize-image-before-upload-secure
Security-hardened fork of the WordPress plugin "Resize Image Before Upload" — removes all ads/promotions and the bundled Swiper 8.2.4 library (CVE-2026-27212, CRITICAL). Core client-side image-resize feature unchanged. G...
keeieb79/CVE-2026-23744-poc
cve-2026-23744 python exploit | language: Python
AzDevops143/FRAGNESIA-Charan-cve-2026-46300
language: C
nikosecurity/CVE-2026-26179
PoC for CVE-2026-26179 / ZDI-26-276, my very own Secure Kernel bug | language: C
Dahalsamir/CVE-2026-23744-MCPJAM-RCE-exploit
This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through t...
suominen/CVE-2026-43284
Tracking Dirty Frag (CVE-2026-43284, CVE-2026-43500), the xfrm-ESP and RxRPC page-cache write LPE chain | topics: cve, linux, security | language: HTML | homepage: https://kimmo.cloud/CVE-2026-43284/
shootcannon/CVE-2026-5076
ARMember Premium <= 7.3.1 Full Admin Account Takeover | language: Python
zs1n/copy-fail-CVE-2026-31431
Exploit for Copy-Fail Vulnerability - Python3 Version | language: Python
0xBlackash/CVE-2026-9082
CVE-2026-9082 | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
duckpigdog/Intelligence-Gathering-Labs
一个“酷炫”的赛博朋克风信息收集 CTF 实验场,面向初学者与红队。 支持离线运行、轻量且开源 | language: PHP | stars: 4 | forks: 2 | updated 2026-02-25T13:01:35Z | pushed 2025-12-16T08:59:47Z
Yn8rt/Befree
一款红队在信息收集时规避IP封禁的傻瓜式一键代理池,通过大量代理节点轮询的代理池工具 | language: C# | stars: 7 | forks: 4 | updated 2026-02-26T01:20:37Z | pushed 2026-02-02T03:46:07Z
bilisheep/ExternalHound
一个基于 FastAPI + React 的企业级资产管理和关系图谱可视化平台 专为渗透测试团队、安全研究人员和红队打造 | language: Python | stars: 18 | forks: 2 | updated 2026-02-28T03:45:13Z | pushed 2026-01-30T02:44:32Z
sangnigege/Awesome_Pentest_Tools
一站式渗透测试与红队工具合集,旨在帮助渗透测试人员打造自己的工具链 | stars: 7 | forks: 2 | updated 2026-03-20T12:58:08Z | pushed 2026-02-28T13:05:29Z
tianlusec/TL-ICScan
TL-ICScan 是由天禄实验室开发的一款面向安全研究人员、红队与蓝队的本地化漏洞情报聚合与分析工具。 | language: Python | stars: 38 | forks: 9 | updated 2026-08-09T01:43:15Z | pushed 2025-12-12T13:37:44Z
D0gekong/Jaegar
Jaegar 是一个基于 LLM (大语言模型) 驱动的全栈式红队自动化侦察与渗透系统。 | language: Lua | stars: 7 | forks: 0 | updated 2026-03-03T15:15:03Z | pushed 2025-12-02T10:16:32Z
ktol1/RedTeam-MCP
RedTeam-MCP: AI-Powered Autonomous Red Team Framework via Model Context Protocol. AI红队与内网渗透自动化框架,支持 gogo, fscan, httpx, nuclei, impacket, playwright 等 15+ 渗透工具,让 LLM 直接化身安全审计黑客。 | topics: active-directory, ai-agent, ai-s...
huaimeng666/gofinger
GoFinger是一款专为红队攻防和企业资产管理设计的下一代web指纹发现、指纹识别工具。基于 Go 语言开发,它不仅继承了传统指纹工具的识别能力,更在性能、可扩展性和输出质量上进行了深度优化。 它旨在帮助安全工程师和渗透测试人员快速、精准地识别网络资产指纹,并以美观、易读的格式呈现结果。工具原生支持本地指纹库与 Fofa、Quake、Hunter 等主流API联动,并集成了 Chainreactors Fingers、Goby、Eho...
25smoking/TaiGong-Project
太公是下一代红队社会工程学基础设施平台 - 全链路钓鱼演练与风险评估系统。支持邮件/短信/IM多渠道投递,内置AI助手,多样化模板库。 | stars: 0 | forks: 0 | updated 2026-06-16T14:24:21Z | pushed 2026-06-16T14:21:44Z
no-one-sec/code-phish
JetBrains系列产品.idea钓鱼反制红队 | topics: redteam, security | language: Go | stars: 330 | forks: 43 | updated 2026-03-07T02:02:06Z | pushed 2026-01-27T17:20:21Z