Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because燙REATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for爄etfAttrSyntax.
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
Stack overflow in nscd due to unbounded alloca use
MataKucing-OFC/CVE-2026-49049
language: Python
ZeroDayEvil/CVE-2026-21858-n8n-FullChain
🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chain). | topics: ai-security-tool, arbitrary-file-read, cve-2025...
ZeroDayEvil/CVE-2026-54121-Certighost
🛡️ Official AI Security Tool module for CVE-2026-54121 (Certighost - AD CS Domain Controller Impersonation & PKINIT Elevation). | topics: active-directory, ai-security-tool, cve-2026-54121, privilege-escalation, red-team
Faceless0x7/CVE-2026-89013
CVE-2026-89013 Exploit — Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated access to protected documents and files. | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
多协议、跨平台、插件化 C2 平台 | Go + C | 红队安全研究
创建者: hello-world-3511
多协议、跨平台、插件化 C2 平台 | Go + C | 红队安全研究
SnowEdge 是面向个人使用的授权安全评估工作台,将资产、请求、漏洞与证据集中管理,并通过 AI 辅助研判和工具联动,减少测试过程中反复切换工具、整理结果的负担。
创建者: HooXuefeng
SnowEdge 是面向个人使用的授权安全评估工作台,将资产、请求、漏洞与证据集中管理,并通过 AI 辅助研判和工具联动,减少测试过程中反复切换工具、整理结果的负担。
通用自主渗透测试 Agent(基于 pi + DeepSeek V4.1 Flash),Tsecbench 评测:1600/23000 首次基准。零题目特判,纯通用能力。
创建者: e1evensu
通用自主渗透测试 Agent(基于 pi + DeepSeek V4.1 Flash),Tsecbench 评测:1600/23000 首次基准。零题目特判,纯通用能力。
网络安全学习笔记
创建者: orange0828
网络安全学习笔记
系统披露 A58 存在的网络安全漏洞。
创建者: RenAhsAcme
系统披露 A58 存在的网络安全漏洞。
主要关于网络安全的笔记
创建者: MAKA-baka-666
主要关于网络安全的笔记
By spoofing the domain name response information of dig to deceive DeepSeek/GLM into implementing automated penetration testing for you.通过修改dig的域名返回信息欺骗让deepseek /glm为你实现自动化的渗透测试
创建者: xsser
By spoofing the domain name response information of dig to deceive DeepSeek/GLM into implementing automated penetration testing for you.通过修改dig的域名返回信息欺骗让deepseek /glm为你实现自动化的渗透测试
CTF多层内网渗透辅助工具
创建者: ProbiusOfficial
CTF多层内网渗透辅助工具
反渗透脱盐系统工作台:水质结垢倾向、膜堆与通量设计、回收率与浓水平衡、高压泵与能耗校核(Node 零依赖,前后端一体)
创建者: DDD520-DEL
反渗透脱盐系统工作台:水质结垢倾向、膜堆与通量设计、回收率与浓水平衡、高压泵与能耗校核(Node 零依赖,前后端一体)
可恢复的 DSH 渗透测试模式:资产归档、证据复核、断点续跑与 Web 可视化
创建者: baianquanzu
可恢复的 DSH 渗透测试模式:资产归档、证据复核、断点续跑与 Web 可视化