Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. Wh
CVE-2026-32693;d9b3d1e0ef96fdb3a027d0aa23a57ea0;In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and c...
Areeba-Zehra-Jafri/CVE-2021-41773---Apache-Path-Traversal---RCE
language: Python
jeffaf/cve-2026-32746
CVE-2026-32746 - GNU InetUtils telnetd LINEMODE SLC Buffer Overflow PoC (pre-auth RCE, CVSS 9.8) | language: Python
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
CVE-2026-33265;b18175af997b2063849bd147b8887e9e
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
CVE-2025-41258;f8841d615582f62447bcd02df9873a14
p3Nt3st3r-sTAr/CVE-2026-2413-POC
language: Python
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in perf_mmap Syzkaller reported a refcount_t: addition on 0; use-after-free warning in perf_mmap. The issu
CVE-2026-23248;828876f3faabdca82919c85aa6b6bbab;In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in perf_mmap Syzkaller reported a refcount_t: addition on ...
Morrizzzzz/RCE_GIS_Academy
In this repo some references and videos are created for RCE colleagues
TEXploited/CVE-2026-21994
toni-bentini/lucity-rce-poc
language: JavaScript
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
derekxmartin/sentinel-edr
SentinelEDR - A proof-of-concept EDR agent for Windows x64 | topics: blueteam-tools, edr, edr-evasion, red-teaming, threat-detection | language: C | stars: 1 | forks: 0 | updated 2026-03-16T00:41:08Z | pushed 2026-03-16T...
KaiiiMonroe/Edraw-Max-Latest-Patch
🛠️ Create clear and professional diagrams effortlessly with Edraw Max, the versatile software for visualizing ideas and enhancing collaboration. | topics: business-diagramming-windows, edraw-max-business-presentation, ed...
david3c2004/CLR-Unhook
🛡️ Bypass EDR/AV hooks in .NET CLR by restoring the original `nLoadImage` function for seamless assembly loading without security inspection. | topics: ai, analytics, awesome, clickhouse, common-lisp, concept-learning, d...
jorrip12/windows
🛡️ Streamline Windows endpoint security with Sentrilite EDR/XDR—real-time threat detection, observability, and AI-driven insights without heavy agents. | topics: button, csharp, debloat, docker, exploitation, exploiting-...
Sahand-Edrisi/sahand-edrisi
language: TypeScript | stars: 0 | forks: 0 | updated 2026-03-16T01:09:25Z | pushed 2026-03-16T01:09:21Z
dre5525/EDRStartupHinder
🛑 Prevent Antivirus and EDR from starting by redirecting core DLLs during Windows startup with EDRStartupHinder for enhanced system control. | topics: amsi-bypass, av-evasion, defense-evasion, dinvoke, edr-evasion, free,...
emmanuel806/CCTV-EDR
topics: bilibili, cctv-detection, cctv-mo, censorship, censorship-circumvention, china-dictatorship, chinese-communist-party, covid-19-china, dictatorship, docker, falun-gong, gfw, github-config, great-firewall, human-ri...
Rakum713/ColdWer
🥶 Freeze EDR/AV processes with ColdWer, using WerFaultSecure.exe PPL bypass to extract LSASS memory on modern Windows systems. | topics: av-bypass, beacon-object-file, bof, cobalt-strike, credential-dumping, edr-bypass, ...
MrSpaghettiBK/rustinel
🔍 Detect threats with Rustinel, a high-performance Windows EDR agent that leverages ETW to collect telemetry and outputs alerts for easy SIEM integration. | topics: api, api-platform, detection-engineering, edr, endpoint...
haydnvn/EdricSongs
language: Python | stars: 0 | forks: 0 | updated 2026-03-16T01:30:10Z | pushed 2026-03-16T01:24:00Z