Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Donalhighnecked528/YellowKey-Bitlocker-CVE-2026-45585
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility. | topics: bitlocker, bitlocker-bypass, bitlocker-drive-encryption, bitlocker-drive-lock, bitlo...
George0Papasotiriou/CVE-2026-11101-HTTP-Cache-Poisoning-via-Unkeyed-Query-Parameter
language: Python
sn0x-sharma/CVE-2026-18718
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector | language: Python
0xBlackash/CVE-2026-46243
CVE-2026-46243
sam00/CVE-2026-56158-.NET-Framework-RCE-PoC-Exploit
language: Python
sam00/POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability
language: Python
sb-ox/repro-OXDEV-77637-uv-workspace
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637 | language: Python
sam00/POC-CVE-2026-32621-Apollo-Federation-XSS-Vulnerability
language: JavaScript
Ch4120N/CVE-2026-3891
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution. | topics: cve-2026-3891, ethical-hacking, penetration-testing, php-web...
sam00/POC-CVE-2026-54121-Certighost
language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Star-233/Waystone
通用问题求解引擎(oritera/Cairn 的 AGPL-3.0 修改版):黑板架构 + 事实-意图图谱,AI 渗透测试验证领域 | language: TypeScript | stars: 2 | forks: 0 | updated 2026-08-10T09:02:32Z | pushed 2026-08-09T08:57:26Z
zar130530/Enterprise-Pentest-Training-Agent
2026实训:企业外网渗透测试实战智能体设计方案(源码与设计方案文档) | language: Python | stars: 0 | forks: 0 | updated 2026-08-10T11:32:24Z | pushed 2026-08-10T11:30:41Z
xiaoyang-xyc/pentest-ops
渗透作战指挥台 — 把渗透情报档案变成可视化作战看板(Hermes 桌面插件 / web dashboard / 独立静态页三形态,数据与展示分离) | language: HTML | stars: 0 | forks: 0 | updated 2026-08-10T16:12:18Z | pushed 2026-08-10T16:11:35Z
HSGQSRGS/WeChat-lm
WeChat-lm是一款全能微信小程序渗透测试工具箱。它可自动扫描本地wxapkg文件,智能识别包类型,支持V1、V2版本解密,通过多线程批量解包并展示实时进度。 工具支持AppID信息查询,搭载48项规则深度扫描手机号、密钥等敏感数据,可解析MD5、AES、SM4等主流加密签名算法。内置JS反混淆引擎,可解码各类混淆代码,精准检测后门、调试接口等隐藏风险逻辑。 其集成mitmproxy双代理套件,可联动Burp工具,支持API模糊测试...
0x7556/hacktool
全平台渗透工具集 支持Windows/Linux/Mac/路由器网络设备,支持MIPS/ARM等架构 | stars: 1 | forks: 0 | updated 2026-08-11T00:42:48Z | pushed 2026-08-10T14:01:42Z
Sexisnull/pobi_v2
前后端分离的 AI 渗透测试 Web 平台(FastAPI + ARQ + 内嵌 pobi_agent 多智能体引擎) | language: Python | stars: 0 | forks: 0 | updated 2026-09-05T06:12:42Z | pushed 2026-09-05T06:12:28Z
923712389/vulnhub
vulnhub渗透 | stars: 0 | forks: 0 | updated 2026-08-11T14:33:29Z | pushed 2026-08-11T14:31:07Z
xiaomaozjj666/web-crawler
Scrapling 风格隐身网页爬虫库:自适应选择器、TLS 指纹隐身 HTTP、JS 渲染与 Spider 框架,内置 JS 逆向 Agent、验证码识别与轻量渗透辅助工具。 | topics: browser-automation, data-extraction, playwright, python, scraper, spider, web-crawler, web-scraping | language: Python | ...
m-sec-org/BreachWeave
智能渗透Agent Manager/Observer/Solver 多角色架构,基于 pi-mono SDK。 | language: TypeScript | stars: 509 | forks: 64 | updated 2026-08-24T08:38:16Z | pushed 2026-08-21T16:08:31Z
Xiong-SJ/JWThacker
面向 CTF 与渗透测试场景的 JWT 攻击与分析工具集,覆盖令牌编解码、签名伪造、常见漏洞验证等核心功能。 | language: Python | stars: 0 | forks: 1 | updated 2026-08-25T07:57:08Z | pushed 2026-08-25T07:54:27Z