Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
sam00/POC-CVE-2026-54121-Certighost
language: Python
Ch4120N/CVE-2026-15409
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user. | topics: couchdb, cve, cve-2026-15409, erlang,...
sam00/POC-CVE-2026-54121-Certighost
fazilbaig1/CVE-2026-26114-Patch
patching N-day of CVE-2026-26114 before microsoft. where microsoft could not patch 100% in many months. but FAC security did it | language: Python
AtlasVector/Certighost-CVE-2026-54121
Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.
jason5545/ghostlock-myron-tw
GhostLock (CVE-2026-43499) kernel exploit port for REDMI K90 Pro Max Taiwan firmware (myron, WPMTWXM) — offsets, build guide, prebuilt binary | language: Python
AtlasVector/Certighost---CVE-2026-54121
Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.
HackSpeak/checkpoint-smartconsole-poc
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing | language: Python
Procjevt/CVE-2026-63030
shinthink/CVE-2026-60004
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1 | topics: code-injection, cve, cve-2026-60004, exploit, forgejo, git, gitea, hook, ...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
QiuKuBoy/WebSiege
Web Application Penetration Testing AI Skill - 面向 AI Agent 的 Web 渗透测试技能,五阶段工作流,OWASP Top 10 全覆盖 | language: Python | stars: 0 | forks: 0 | updated 2026-08-12T09:27:44Z | pushed 2026-08-12T09:26:17Z
wangyu-wycc/web-penetration-risk-assessment
模拟乙方安全服务流程完成企业Web应用渗透测试与风险评估项目。遵循正规渗透测试授权流程,完成信息收集、漏洞探测、人工漏洞复现、风险分级、输出整改方案,最终生成标准化安全评估报告。 | stars: 0 | forks: 0 | updated 2026-08-13T12:48:03Z | pushed 2026-08-13T12:48:00Z
Netw0rkNoob/VulnClaw
基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。 | topics: ai, ai-agent, ai-tools, ctf, cybersecurity, openclaw, penetration-testing, penetration-testing-tools, security-tools, s...
yanxinwu946/penelope-fork
Penelope 二开:后渗透工具统一管理 + 本地缓存 + 自动跟随 latest | language: Python | stars: 1 | forks: 0 | updated 2026-08-12T13:28:36Z | pushed 2026-08-12T13:28:01Z
atk7r/Xunji
面向 Claude Code 的渗透 / 红队 Harness | language: Python | stars: 3 | forks: 0 | updated 2026-08-12T22:02:28Z | pushed 2026-08-12T22:02:23Z
JiuZero/AetherAgent
Aether 是一套基于大模型的自主渗透测试执行系统,通过 Planner–Executor–Reflector(P-E-R)多智能体协作闭环,将渗透测试从"人工逐条下发指令"推进到"任务级自主规划、并行执行、证据驱动收敛、可人工干预"的自动化阶段。 本仓库为 AetherAgent 开放展示仓库:公开设计文档与发行产物,不包含源代码与构建流程。 | language: Dockerfile | stars: 0 | forks: 0 ...
Kayoko-oni/AirCombat
AirCombat是一个基于Open3D的无人机集群攻防仿真系统,实现雷达/侦察视野下的自动对抗与策略规划。 | language: Python | stars: 3 | forks: 1 | updated 2026-06-25T03:14:57Z | pushed 2026-08-06T09:54:45Z
HIT-Fireworks/22CS31200
网络攻防技术A课程资料(1 个逻辑资源分组,1 个课程代码) | stars: 0 | forks: 0 | updated 2026-08-11T08:06:55Z | pushed 2026-08-11T08:06:45Z
xjinya-xiangwu/AI-Native-Cyber-Range
AI 安全攻防演练平台 · Agent-Native 作战回路演示(GitHub Pages 静态托管) | language: JavaScript | stars: 0 | forks: 0 | updated 2026-08-13T02:16:49Z | pushed 2026-08-13T02:16:46Z | homepage: https://ai-native-cyber-range.vercel.app
xk11z/plutoxAI
本系统基于 **Windows + WSL (Kali Linux)** 双环境搭建,是一套整合多类AI安全工具的一体化渗透测试平台。系统将大语言模型能力与传统渗透测试工具深度结合,覆盖Web安全、内网攻防、二进制逆向、API测试、流量分析等多个安全领域,可实现渗透测试全流程的智能化、自动化提效。 | topics: ai-hacking, ai-pentesting, ai-security, ai-tools, pentest-to...