Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
theopaid/CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
theopaid/CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille
Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)
theopaid/CVE-2026-66746-HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille
Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)
theopaid/CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field
Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field | language: Python
sfewer-r7/CVE-2026-16232
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token. | language: Python
darses/CVE-2026-50522
Microsoft SharePoint CVE-2026-50522 | language: ASP.NET
ivmks74/IIITA-IoT-Security-Research
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
tc4dy/CVE-2026-53921-PoC-Exploit
CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) 🛡️ Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE. Dual-vector (IA_NA/IA_PD) overflow with MIPS/ARM shellcode, ROP chains, S...
mumaosong/CVE-2026-43499-xiaomi_8e-GUI
CVE-2026-43499-xiaomi_8e密钥离线计算客服端,网页端:miauth.mu667.ccwu.cc | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
kuaiyelink/HalberdStrike
HalberdStrike由快页佚名实验室开发,基于PenTestGPT思想,使用大语言模型驱动三模块协作架构实现的端到端自动化渗透测试工具 | language: Python | stars: 3 | forks: 0 | updated 2026-07-25T06:06:57Z | pushed 2026-07-25T06:06:35Z
wnm795/AI-Recon-Agent
AI渗透测试信息收集 Agent,基于 LangGraph 状态驱动工作流,支持自然语言对话和 CLI 直扫。集成被动信息收集、主动扫描、NVD/CVE 向量知识库、漏洞匹配与 Markdown 报告生成,支持环境自检、缓存管理和快速同步 CVE 数据。 | language: Python | stars: 1 | forks: 0 | updated 2026-07-26T07:18:15Z | pushed 2026-07-26T...
wangzifan396-wzf/security-viz-lab
网络安全可视化实验室 - DDoS、SQL注入、XSS/CSRF、渗透测试、WAF、IDS/IPS、蜜罐、零信任 | topics: computer-science, csrf, css, cybersecurity, data-viz, ddos, education, html, interactive, javascript, single-file, software-engineering, sql-injection, s...
shuaiqideyu/SecAtlas
结构化中文网络渗透知识库:技术卡、专题、案例与多 Agent 协作维护 | topics: ai-agents, api-security, application-security, blackmule, chinese, cloud-security, ctf, cybersecurity, cybersecurity-learning, infosec, knowledge-base, network-security, pene...
SilasWu50/WebScanner-with-AI
这是一款接入ai分析的集成信息收集工具,集成了多个主流github上优秀的信息收集工具,并通过ai进行自动化信息整理,精准高效暴露突破口给予渗透人员 | language: Python | stars: 3 | forks: 1 | updated 2026-07-28T00:07:30Z | pushed 2026-07-26T07:12:24Z
YHalo-wyh/AegisCabinet-Zero
校园零信任智能外卖柜攻防仿真系统:Schnorr ZKP、侧信道、重放攻击与固件溢出防护 | topics: cybersecurity-education, iot-security, schnorr, streamlit, zero-trust | language: Python | stars: 0 | forks: 0 | updated 2026-07-15T13:22:16Z | pushed 2026-07-15T13:...
HWBoy-J/AT-D
AT&D 红客攻防系统融合深度学习与大数据分析,提供靶场演练、入侵检测、漏洞扫描等功能,有效防御各类网络攻击,并具备自动漏洞修复、攻击溯源、文件分析等特性 | language: CSS | stars: 1 | forks: 0 | updated 2026-08-09T01:08:25Z | pushed 2026-07-15T17:51:25Z
sxtyxt/tianyan_OS
天衍 OS 是一个面向网络安全攻防一体化的 Rust 裸机操作系统。它采用微内核 + 独立 Capsule 架构,在单一系统内同时集成红队攻击能力、蓝队防御能力、AI 自主决策与 C2 指挥调度,适用于攻防演练、自动化渗透测试、安全研究等场景。 | stars: 0 | forks: 0 | 2026-07-15T20:34:34Z
MWDLH/Full-stack-cybersecurity-expert
AI Agent 全栈安全协议 — 非提示词,而是一套可执行的攻防规范。红/蓝/审计/咨询四模式切换,含状态管理(断点续传)、Token 斩断、防幻觉自检、11 类操作安全红线。15 平台场景覆盖 AD/云/移动。 | language: Markdown | stars: 2 | forks: 0 | updated 2026-07-29T01:59:06Z | pushed 2026-07-16T01:36:05Z
kookisky/jinghuacheng
京華城案15場言詞辯論逐字稿與分析|檢辯攻防完整紀錄 | topics: court-debate, jinghuacheng, ke-wenzhe, taiwan-judiciary, transcript | language: HTML | stars: 0 | forks: 0 | updated 2026-07-16T07:20:24Z | pushed 2026-07-16T07:51:40Z | homepage: htt...