Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
MadExploits/CVE-2026-14483
CVE-2026-14483 POC EXPLOIT BY MADEXPLOITS | language: Python
aj2108/CVE-2026-9833
IlhomjonR/CVE-2026-67595
CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection. | topics: cve, infosec, security, supply-chain-security, vaahcms, vulnerability-research ...
yellowkeybitlocker/YellowKey-Bitlocker-CVE-2026-45585
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. ...
martincifu/YellowKey-Bitlocker-CVE-2026-45585
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. ...
0xmrma/CVE-2026-5061
Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the link between those operations turned an in-sandbox file reference into ...
0xmrma/CVE-2026-14361
Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output to escape the intended directory and overwrite a preexisting file.
envincion1991-cmyk/CVE-2026-51954
Vulnerability Research
0xBlackash/CVE-2026-64531
CVE-2026-64531 | language: Python
7h30th3r0n3/CVE-2026-53625-GLPI-PoC
GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full control of any Super-Admin account through REST API authtype manipulatio...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
AgentZero2002/LLMAlignment
THU大语言模型 Part III: 对齐与后训练 | SFT/RLHF/DPO/ConstitutionalAI/安全红队/评估/LoRA/偏好数据/对齐税/Superalignment | 16章Python+NumPy | language: Python | stars: 0 | forks: 0 | updated 2026-07-27T09:25:33Z | pushed 2026-07-27T08:54:52Z
d558mju7m2/mUPjhzRyTW
【Java计算机毕业设计分享】基于SpringBoot+Vue浏览器攻防平台,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 0 | forks: 0 | updated 2026-07-26T18:26:51Z | pushed 2026-07-26T18:26:48Z
AIJobpublic/hackingtool-defense-guide
🛡️ 從攻擊者角度學習 190+ 駭客工具,強化你的網站防禦能力 | HackingTool 攻防教學 | language: HTML | stars: 0 | forks: 0 | updated 2026-07-27T10:28:19Z | pushed 2026-07-27T10:27:33Z
b9767te1al/XFfbsJpU
【Java计算机毕业设计分享】基于SpringBoot+Vue浏览器攻防平台,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 1 | forks: 0 | updated 2026-07-27T14:58:58Z | pushed 2026-07-27T14:57:52Z
YunSeeTeam/YunSeeTeam.github.io
YunSee CTF 战队官网 — 攻防对抗 / 漏洞研究 / 安全竞赛。纯静态,零构建零依赖。 | language: CSS | stars: 0 | forks: 0 | updated 2026-08-05T09:12:11Z | pushed 2026-08-05T09:11:17Z
将时间维度暂留视觉 + 物理拖拽迷宫 + 语义/算力蜜罐三者结合的创新性反 AI 验证码开源组件
创建者: Z-V-I
将时间维度暂留视觉 + 物理拖拽迷宫 + 语义/算力蜜罐三者结合的创新性反 AI 验证码开源组件
燕云十六声兑换码批量自动填写工具。纯 Python 标准库,绕过输入法拦截,无需 OCR 即可判断兑换结果。
创建者: yunyi-zhao
燕云十六声兑换码批量自动填写工具。纯 Python 标准库,绕过输入法拦截,无需 OCR 即可判断兑换结果。
fastjson2 ≤ 2.0.62 利用多态反序列化(ObjectReaderSeeAlso)+ URLClassLoader.findClass 点号转斜杠替换,绕过 AutoType 白名单及 JDK ClassLoader.checkName,实现远程代码执行。
创建者: heart147
fastjson2 ≤ 2.0.62 利用多态反序列化(ObjectReaderSeeAlso)+ URLClassLoader.findClass 点号转斜杠替换,绕过 AutoType 白名单及 JDK ClassLoader.checkName,实现远程代码执行。
Fail2ban for modern Linux (Debian 12+, Alpine, Rocky) - 最简单的防止SSH暴力破解的脚本
创建者: cnnlei
Fail2ban for modern Linux (Debian 12+, Alpine, Rocky) - 最简单的防止SSH暴力破解的脚本
VulnFlanker 是一个面向内部安全运营的漏洞影响评估与受控验证平台。它将漏洞情报、主机资产快照、资产与漏洞匹配、风险优先级排序、只读验证任务和审计日志连接为一套完整工作流。
创建者: ZonWin
VulnFlanker 是一个面向内部安全运营的漏洞影响评估与受控验证平台。它将漏洞情报、主机资产快照、资产与漏洞匹配、风险优先级排序、只读验证任务和审计日志连接为一套完整工作流。