Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
TomorrowX6/CVE-2026-63030-poc
language: Python
EQSTLab/CVE-2026-33017
Langflow RCE | language: Python
4B3R4M4-607D/CVE-2026-63030-POC
CVE-2026-63030 / wp2shell | language: Python
srkyn/nginx-map-risk-audit
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence. | topics: cve-2026-42533, detection-engineering, microsoft-defender, nginx, splunk, vulnerability-manageme...
administrator-01001/CVE-2026-63030
Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1). | language: Python
hidden-investigations/wp2shell-scanner
WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export. | topics: cve-2026-60137, cve-2026-63030, penetration-testing, security-scanner, vul...
eyesecurity/wp2shell-compromise-scanner-plugin
Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137) | language: PHP
ZenithGenius/wordpress-batch-rce-lab
CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab. | language: HTML
0xBlackash/CVE-2026-63030
CVE-2026-63030 | language: Python
ananay/wp2shell-lab
Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain | language: PHP
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Janice-zls/Driving-Effects-of-NEV-Penetration-on-Automotive-Chip-Market
新能源汽车渗透率对中国汽车芯片市场的驱动效应实证分析 本项目深度锚定国家半导体自主可控、汽车产业转型升级核心战略,聚焦全球半导体产业重构、国内新能源汽车渗透率持续攀升、汽车芯片市场加速扩容的产业大背景,针对当前学界与业界对新能源汽车带动芯片市场增长的研究短板开展专项实证研究。现阶段相关研究多为定性趋势分析,普遍存在产业传导逻辑拆解不清晰、驱动效应无法量化、核心影响因子识别模糊、产业动态演化特征刻画缺失等问题,难以精准支撑我国汽车芯片产业...
guaidao2/suidexp
玄幕安全团队创始人guaidao2开发的基于GTFOBins的自动化渗透测试提权框架。 | language: Shell | stars: 2 | forks: 0 | updated 2026-07-06T12:43:50Z | pushed 2026-07-04T05:30:56Z
ramariyata/QddwHOKPzB
【Java计算机毕业设计分享】基于Python的后渗透框架设计与实现,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】 | stars: 0 | forks: 0 | updated 2026-07-06T14:53:11Z | pushed 2026-07-06T14:49:40Z
jenn619/frida_Hook_tools_Android
基于 [Frida](https://frida.re/) 的 Android 应用安全分析工具集,运行时自动捕获加密/哈希参数,监控网络请求、WebView、动态加载等行为,并内置 Root/模拟器检测绕过。该项目适合渗透测试人员,遇到加了挺牛b的壳的app绕不过也正常,倘若目标app把类名做了混淆,可以把混淆后的类名与脚本中的类名做替换 | language: JavaScript | stars: 8 | forks: 0 | u...
opsqw/scoop-security
Scoop bucket for Penetration Testing and Cybersecurity related tools. 用于渗透测试和网络安全相关工具下载、安装和自动更新的Scoop软件仓库。 | topics: cybersecurity, cybersecurity-tools, pentesting, pentesting-tools, scoop, scoop-bucket, security, securi...
Hmx-7488/testing-security
面向后端的一站式安全审计 Skill:从风险分析到 P0 功能测试、一键回归、八维攻防渗透、漏洞报告。不算返回码,只验计算结果对不对。 | stars: 0 | forks: 0 | updated 2026-07-20T09:05:56Z | pushed 2026-07-07T02:59:29Z
ok-helloworld/vibe-pentest
Vibe Pentest(AI 渗透测试)是一款基于 AI Agent 架构的自动化渗透测试工具,采用多 Agent 并行执行架构,能够对 Web 应用、API、管理后台等进行全面的黑盒渗透测试(包括业务逻辑漏洞评估),输出稳定可靠的安全报告,并提供可落地的整改建议。 | topics: ai-pentest, vibe-pentest | language: Python | stars: 205 | forks: 22 | upda...
zhaoxuya520/reverse-skill
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, ...
cha0upup/LeoAI
AI 驱动的后渗透综合管理平台,深度集成 LLM Agent,开箱即用。 | language: Java | stars: 279 | forks: 32 | updated 2026-08-12T13:44:50Z | pushed 2026-08-12T10:40:09Z
Unclecheng-li/VulnClaw
基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。 | topics: ai, ai-agent, ai-tools, ctf, cybersecurity, openclaw, penetration-testing, penetration-testing-tools, security-tools, s...