momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 4729 条情报 漏洞监控 2952 / 网安开源项目 1545 / 威胁情报 232

漏洞监控

来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。

2952总量

网安开源项目

优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。

1545总量

威胁情报

来自 360、奇安信、斗象等官方站点的公开情报聚合。

232总量
CEAarab/CVE-2026-26026-PoC
language: Shell
taielab/ArmsIndex
Red Team Arsenal Manager - 红队武器库管理平台 | stars: 5 | forks: 0 | updated 2026-04-19T00:15:01Z | pushed 2026-04-16T06:09:07Z
Axios npm 供应链攻击从TTP层面特征的归属分析
近日,热门JS库axios遭供应链攻击,攻击者劫持维护者npm账户,发布含恶意依赖plain-crypto-js@4.2.1的1.14.1/0.30.4版本。技术特征(预部署诱饵包、多平台载荷、反取证手段)与朝鲜LABYRINTH CHOLLIMA组织高度吻合,多家安全机构高置信度将攻击归因于该组织。
kaleth4/CVE-2026-33826
language: Python
Clearzero22/security-tools
🔐 网络安全工具集合 - 端口扫描、HTTP头分析、目录扫描、SQL注入测试工具(教育用途) | topics: bun, cybersecurity, educational, network-security, penetration-testing, security-tools, typescript, web-security | language: TypeScript | stars: 0 | forks: 0 | upd...
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)
This is the fifth update to the TeamPCP supply chain campaign threat intelligence report, "When the Security Scanner Became the Weapon" (v3.0, March 25, 2026). Update 004 covered developments through March 30, including ...
kaleth4/CVE-2026-33825
language: Python
eason204646-droid/dunhu
盾护安全工具,完全免费开源,扫描并检测你的浏览器安全性! | language: HTML | stars: 1 | forks: 0 | updated 2026-04-10T09:38:15Z | pushed 2026-04-10T09:38:12Z
高危风险提示|又是供应链攻击!Axios npm包遭投毒,请尽快排查处置
Axios npm包遭供应链投毒,恶意版本植入RAT木马窃取凭据,请速排查处置。
kaleth4/CVE-2026-33827
language: Python
ktol1/RedTeam-Agent
RedTeam-Agent: AI-Powered Autonomous Red Team Framework via Model Context Protocol. AI红队与内网渗透自动化框架,支持 gogo, fscan, httpx, nuclei, impacket, playwright 等 15+ 渗透工具,让 LLM 直接化身安全审计黑客。 | topics: active-directory, ai-agent, ai...
AI一句话挖出Vim RCE?还缺亿点点细节
立即查看详情 →
mobilehackinglab/CVE-2026-0006-openapv-poc
CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8 | language: C
however-yir/howeverpromptfoo
HoweverPromptfoo:面向企业场景的 LLM 评测与红队测试框架 | language: TypeScript | stars: 1 | forks: 0 | updated 2026-04-21T16:01:03Z | pushed 2026-04-26T22:52:49Z
ISC Stormcast For Wednesday, April 1st, 2026 https://isc.sans.edu/podcastdetail/9874, (Wed, Apr 1st)
EQSTLab/CVE-2026-33937
language: HTML
SultanSah/-Taixu-Framework-Autonomous-Agent-Capital-AAC-2.0
把东方修仙神话的宏大叙事,硬核地转化为可落地、可扩展的现代 AGI(通用人工智能)工程蓝图。 构建一个以“硅基修仙”为底层逻辑的完全自治型 AI 资本实体架构。通过引入“洗髓”(上下文动态修剪)、“藏经”(高维向量检索)、“自创功法”(沙盒工具生成)与“渡劫”(RLHF/红队测试)机制,解决大模型记忆坍塌、算力冗余及涌现不可控的业界难题,实现 AI 代理的无限成长与跨国资本运作。 | language: Python | stars: ...
Multiple Vulnerabilities in Apple Products Could Allow for Privilege Escalation
<p>Multiple vulnerabilities have been discovered in Apple products, the most severe of which could allow for privilege escalation. Successful exploitation of the most severe of these vulnerabilities could allow a user to...
truekas/ls-poc
CVE-2026-30368 proof of concept | language: JavaScript
lyu549601-design/my-repo
AI红队测试项目 | language: Python | stars: 0 | forks: 0 | updated 2026-04-09T18:28:18Z | pushed 2026-04-08T07:25:50Z
OpenClaw又又又危!Axios npm被投毒,植入全平台木马
今日,Axios这个年下载量超36亿、JavaScript 生态最核心的依赖之一,在 npm 仓库遭遇供应链投
John-Jung/CVE-2026-25604-PoC
A PoC for demonstrating CVE-2026-25604 | language: Python
wodefox/KALI-Skill
将openclaw打造成自主红队 | language: Python | stars: 1 | forks: 0 | updated 2026-04-09T10:31:56Z | pushed 2026-04-06T04:48:10Z
Coruna与DarkSword:iOS高端攻击武器扩散的威胁
2026年3月,安全团队披露两款iOS零日漏洞利用工具包Coruna和DarkSword,这两款本属高级间谍武器的工具目前已经二手市场扩散至多个犯罪团伙,严重威胁普通用户安全。
Race Condition in GNU Sed
biaomian09/biaomian
自写安全工具 | stars: 0 | forks: 0 | updated 2026-04-09T06:36:51Z | pushed 2026-04-09T06:36:45Z
Application Control Bypass for Data Exfiltration, (Tue, Mar 31st)
In case of a cyber incident, most organizations fear more of data loss (via exfiltration) than regular data encryption because they have a good backup policy in place. If exfiltration happened, it means a total loss of c...
John-Jung/CVE-2026-26903-PoC
A PoC for demonstrating CVE-2026-26903 | language: HTML
skeleton2024/ironclad-decision-engine
对抗式理性决策引擎:递归任务拆解 + 红队审计 + 蒙特卡洛仿真 | language: Python | stars: 1 | forks: 0 | updated 2026-04-09T06:06:46Z | pushed 2026-03-23T11:31:34Z
ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st)