Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
SimoesCTT/SCTT-2026-33-0007-The-OLE-Vortex-Laminar-Bypass
Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply opens a file. They think their "Service-side change" for Office 2021+ is a...
sastraadiwiguna-purpleeliteteaming/Dissecting-CVE-2026-0628-Chromium-Extension-Privilege-Escalation
Origin CyberAnatomy Spoofing via Malicious WebView - Dissecting CVE-2026-0628 Chromium Extension Privilege Escalation This research provides a comprehensive technical dissection of CVE-2026-0628, a high-severity privileg...
otakuliu/CVE-2026-22807_Range
CVE-2026-22807的靶场 | language: Python
SimoesCTT/SCTT-2026-33-0004-FortiCloud-SSO-Identity-Singularity
While Fortinet's January 27, 2026 mitigation for **CVE-2026-24858** focuses on blocking specific accounts like `cloud-noc@mail.io`, it fails to address the **Temporal Vulnerability** of the SAML state machine. | language...
TryA9ain/CVE-2026-24061
CVE-2026-24061 Batch Scanning Tool | language: Python
Jvr2022/CVE-2026-25126
CVE-2026-25126 Proof-of-Concept demonstrating vote count manipulation in PolarLearn due to improper runtime validation of the forum vote direction parameter. Published after upstream patch release. | language: JavaScript
SimoesCTT/SCTT-2026-33-0002-DWM-Visual-Field-Singularity
Microsoft just patched CVE-2026-20805 and CVE-2026-20871 in January 2026 to stop "Information Disclosure" and "Use-After-Free" bugs in DWM. They think they've secured the "Visual Boundary." We are about to prove that a 3...
SimoesCTT/-SCTT-2026-33-0002-DWM-Visual-Field-Singularity
### 📡 Theoretical Classification **ID:** SCTT-2026-33-0002 **Researcher:** Americo Simoes (SimoesCTT) **Physics:** Theorem 4.2 - Turbulent Phase Transition (TPT) **Constant:** α = 0.0302011 **Target:** Desktop Window Man...
ii4gsp/CVE-2026-1457
CVE-2026-1457 is an authenticated buffer overflow vulnerability in the web API of TP-Link VIGI C385 V1. This vulnerability allows authenticated attackers to perform remote code execution (RCE).
otakuliu/CVE-2026-24841_Range
CVE-2026-24841仿真靶场,用来模拟真实环境,适合搭建Dokploy报错而无法搭建的 | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
当前条件下没有命中网安开源项目。