Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
ivanesk315/CVE-2026-20253
language: Python
zenyxx-xd/RootMyVivo-Exploit
GhostLock (CVE-2026-43499) exploit fork for RootMyVivo Neo — iQOO Neo 11 (PD2520, SM8750, 6.6.89). For authorized research on own devices only. | language: C
Saku0512/CVE-2026-72815-poc
language: Go
Soskalai/CVE-2026-77578
PoC for CVE-2026-77578 - Authenticated Arbitrary Local File Read in Xibo CMS | topics: cve, exploit, offensive-security, path-traversal, poc, vapt, xibo-cms | language: Python
BrainBob/CVE-2026-76578
language: Python
Xrzmodz444/cve-2026-41940-PoC-Linux
CVE-2026-41940 PoC - Linux/Termux Compatible Version | language: Python
abraxas/CVE-2026-11387-WooCommerce-SMS-OTP
SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation (Forced Password Reset) | language: Python
Chromium: CVE-2026-85046 V8 中的类型混淆
<p>该 CVE 由 Chrome 分配。Microsoft Edge(基于 Chromium)采用了 Chromium,已解决此漏洞。有关更多信息,请参阅 <a href="https://chromereleases.googleblog.com/2026">Google Chrome 发布说明</a>。</p>
Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
wumingzhinu/esp32-wifi-penetration-tool-cn
ESP32 Wi-Fi 渗透测试工具 - 中文汉化 + ESP32-C3 移植版:深色 UI、JSON API(逻辑全在 C 端)、PMKID/握手捕获、解除认证攻击、客户端探测 | language: C | stars: 0 | forks: 0 | updated 2026-09-09T10:09:00Z | pushed 2026-09-09T10:08:13Z | homepage: http://192.168.4.1
Punhacker/CyberOrchestra
智能化渗透 | language: Python | stars: 1 | forks: 0 | updated 2026-09-09T10:11:48Z | pushed 2026-09-09T10:12:57Z
Qitangwen/cs-internal-pentest
4层隔离内网环境下的Cobalt Strike渗透测试 | topics: cobalt-strike, cybersecurity, internal-network, penetration-testing, red-team | stars: 0 | forks: 0 | updated 2026-09-09T10:31:48Z | pushed 2026-09-09T09:24:14Z
Yuk1you/PenT3st
渗透测试实战工作流 skill for Claude Code - 5阶段方法论/19类攻击playbook/2887份H1真实案例/国产组件指纹库 | stars: 29 | forks: 7 | updated 2026-09-17T03:02:08Z | pushed 2026-09-14T06:11:03Z
xiaoguai009/codex-armor-toolkit
Codex 全破甲|面向 GPT-6 Astra 的指令配置工具,适用于渗透测试、逆向分析与开发工作流。 | topics: codex, gpt-6-astra, penetration-testing, prompt-configuration, reverse-engineering, windows | language: Python | stars: 66 | forks: 11 | updated 2026-09-18T1...
lyyee0/qiye-RAG
基于简化内存的win11 x64 专业版系统下的网页靶机,主要模拟企业在原生安全下的RAG系统是否存在风险泄露的情况,更多的运用于智能攻防模拟 | stars: 0 | forks: 0 | updated 2026-09-09T13:58:16Z | pushed 2026-09-10T04:45:01Z
ddzyx/qiuxiaoce-football-dataset
欧洲五大联赛(英超/西甲/意甲/德甲/法甲)历史比赛攻防统计与赛果开放研究数据集 (球小策数据中心清洗发布) | topics: football-dataset, machine-learning, premier-league, qiuxiaoce, soccer, sports-analytics, sports-data | language: Python | stars: 0 | forks: 0 | updated 202...
cycode0527/WebAgent
一个用于AI攻防的Agent | language: Python | stars: 0 | forks: 0 | updated 2026-09-08T03:31:53Z | pushed 2026-09-08T03:31:46Z
GHhuang1057/breakfront
BREAKFRONT 破阵前线:Minecraft (Fabric 1.21.1) 32v32 大战场整合包——攻防模式玩法核心 breakfront + 客户端 breakfront-client,GitHub Actions 构建 | language: Java | stars: 0 | forks: 0 | updated 2026-09-18T17:23:59Z | pushed 2026-09-18T17:26:09Z
MYHmys/AiST
基于 Wails 框架开发的 AI 驱动 API 接口渗透测试桌面工具,集成 MCP 工具扩展、AI 智能分析、xray 漏洞扫描、Nuclei 漏洞扫描、目录扫描、信息收集六大检测引擎,支持 MITM 流量拦截、自动化漏洞发现与验证、Markdown 报告导出。AI Agent 通过 MCP 协议连接云 VPS 的工具服务,实现主动发包获取真实响应后分析,突破传统静态分析的局限。 **支持多种 AI 平台**:DeepSeek、通义千...