Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under
CVE-2026-58039
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security bound
CVE-2026-56847
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vuln
CVE-2026-56850
tfawnies/CVE-2026-68771
language: Python
Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
CVE-2026-59251
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
地震应急响应与救援力量调度平台(Go 标注题基线)
创建者: VanceMichael
地震应急响应与救援力量调度平台(Go 标注题基线)
地震应急响应与救援力量调度平台(Go 标注题基线)
创建者: VanceMichael
地震应急响应与救援力量调度平台(Go 标注题基线)
地震应急响应与救援力量调度平台(Go 标注题基线)
创建者: VanceMichael
地震应急响应与救援力量调度平台(Go 标注题基线)
lukethecat/stalker
agent0 信息采集与结构化存储 · agent1 红队闭环与蓝队策略 | language: JavaScript | stars: 0 | forks: 0 | updated 2026-08-17T10:16:15Z | pushed 2026-08-17T10:14:40Z
DyNooob/ForensicsPP
Forensics++ is a local-first browser workbench for CTF/MISC, lightweight forensic triage, encoding and decoding, metadata inspection, hashes, archives, SQL dumps, and network evidence previews. Website: https://www.foren...
bobo663/CodeGuard-AI
CodeGuard AI 是一个 **Multi-Agent(多智能体)协作**的代码审查平台,利用大语言模型(LLM)对上传的代码进行自动化质量检查、安全漏洞扫描、性能分析和自动修复生成。 | language: Python | stars: 2 | forks: 0 | updated 2026-08-25T06:21:15Z | pushed 2026-08-13T04:23:30Z
Lincisaironegg/quake_scan
调用360quake资产探测api,实现对关键字、ip进行资产收集、简单漏洞扫描及LLM相关性评分 | language: Python | stars: 1 | forks: 0 | updated 2026-08-13T10:19:22Z | pushed 2026-08-13T10:01:29Z
uckkk/dsh-dependency-audit
依赖安全审计:OSV.dev 漏洞扫描 + npm 过期依赖检测,返回严重级/修复版本/升级幅度 | topics: deepseek-harness, dsh-plugin | language: JavaScript | stars: 0 | forks: 0 | updated 2026-08-19T15:31:08Z | pushed 2026-08-19T15:17:29Z
AWY-Cipher/MrCipher
**MrCipher 是一款一体化的综合漏洞扫描与资产测绘工具**,把"主机发现 → 端口扫描 → 协议识别 → 子域枚举 → Web 指纹探测 → 漏洞检测 → 后渗透验证"整合成一条流水线,面向红队 / 安服 / 授权自检场景,提供 **命令行、交互式控制台、Web 界面(-ui)** 三种使用方式。 它的核心特点是:**自带一套 Go 原生重新实现的 MSF(Metasploit)风格模块系统**,并且把多个知名开源安全工具的优秀...
plus-w/Football-Tactics-Board
一款足球战术板与AI推演工具 —— 真实球员数据导入、阵型与首发配置、拖拽攻防推演,离线可用,内置AI战术分析助手,(Football Tactics Board — a zero-build, offline-first web app for football tactics: real squad data, formation & lineup config, drag-and-drop match analysis, plus...