Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
lzty/CVE-2026-94129
A POC for CVE-2026-94129 | language: Rust
murrez/CVE-2026-90817
Unauth REDCap RCE (CVE-2026-90817) mass check PoC — requires public survey hash for full validation. | topics: cve-2026-90817, poc, python, redcap, security, vulnerability-scanner | language: Python
zi4nc4/CVE-2026-68376
language: HTML
HORKimhab/CVE-2026-74469
CVE-2026-74469 DiagSpill | language: Python
HORKimhab/CVE-2026-68121
CVE-2026-68121 PPPoEject | language: Python
HORKimhab/CVE-2026-81000
CVE-2026-81000 | language: Python
HORKimhab/CVE-2026-80844
CVE-2026-80844, DirtyAH6 | language: Python
nimaarek/CVE-2026-8932-PoC
CVE-2026-8932 PoC - incomplete mTLS config matching in conn reuse | topics: libcurl, poc, vulnerability | language: C | homepage: https://curl.se/docs/CVE-2026-8932.html
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
tarfile hardlink fallback ignores custom extraction filter rejection via None
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
mengqi0815/metro-dashboard
地铁渗透率看板 - 44城地铁日维度/月维度渗透率分析 | language: JavaScript | stars: 0 | forks: 0 | updated 2026-09-21T08:31:26Z | pushed 2026-09-21T08:31:22Z
yzdily/domain-pentest
AI 安全测试框架的**域渗透(Active Directory / 内网渗透)**技能包,覆盖 P1 侦察 → P8 报告共八个阶段的方法论、阶段判据与工具调用约定 | topics: security | language: Python | stars: 0 | forks: 0 | updated 2026-09-21T14:13:10Z | pushed 2026-09-21T14:13:06Z
r0th-m/artex-ymh
ARTEX 二次开发版:外网突破→内网纵深全流程自主渗透平台(上游 Autumn-27/ARTEX,AGPL-3.0) | language: Go | stars: 6 | forks: 1 | updated 2026-09-21T15:45:03Z | pushed 2026-09-19T16:09:18Z
youayou-Lee/SibylPent
Evidence-first, prediction-locked AI web pentest framework | 先写预言再落动作的 AI Web 渗透框架(设计阶段 PLAN-ONLY) | stars: 0 | forks: 0 | updated 2026-09-21T15:59:02Z | pushed 2026-09-21T18:31:42Z
Alanener/Plumboo
黑盒渗透认知 Runtime:只替你记住世界,不替你决定怎么打。IO / 状态 / 投影 / 记账,证据可复核 | language: Python | stars: 13 | forks: 0 | updated 2026-09-24T21:17:38Z | pushed 2026-09-21T19:04:45Z
Github推送中心
创建者: akash0x00
Unauthenticated SQL injection to RCE exploit for ZoneMinder 1.29/1.30 (CVE-2016-10204, EDB-41239). Single-command SQLi to webshell to reverse shell PoC in Python.
Github推送中心
创建者: boom5497
2022计算机毕设一套 终稿 (论文+程序源代码+使用说明)一款支持通过规则扩展进行终端防护对抗的后渗透框架设计与实现_596a004a-efc5-4543-a2ed-82b6a5ad11f5.zip
Github推送中心
创建者: s0m30ne
A deliberately vulnerable Spring Boot business app for learning Java code audit and exploitation. 面向新手的 Java 传统漏洞代码审计与利用靶场
Github推送中心
创建者: dnasdw
B站关注动态聚合器 Tampermonkey 脚本:聚合全部关注UP的视频(投稿+动态视频),绕过75天历史限制,全量补课+增量归档 | Tampermonkey userscript that aggregates all followed creators' videos beyond bilibili's 75-day feed limit
Github推送中心
创建者: novaestellar
新信微 — 统一网络侦察引擎. WAF绕过 · 并行抓取 · Dork数据库 · 15平台路由.