Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Chromium: CVE-2026-17758 Heap buffer overflow in Dawn
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17809 Insufficient validation of untrusted input in Extensions
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17810 Uninitialized Use in Dawn
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17812 Inappropriate implementation in DigitalCredentials
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17819 Inappropriate implementation in WebAppInstalls
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17822 Inappropriate implementation in Chrome for iOS
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17825 Insufficient policy enforcement in Passwords
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17837 Insufficient validation of untrusted input in DevTools
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17853 Inappropriate implementation in DevTools
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-17917 Policy bypass in Chrome for iOS
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
hitsz-ids/AI-Course
The repository for high school AI course | language: Python | stars: 8 | forks: 2 | updated 2026-08-19T16:31:35Z | pushed 2026-08-19T16:28:22Z
Andyyyyuan/CVE-Poc
存放一些渗透打靶中积累的CVE-poc | language: C | stars: 0 | forks: 0 | updated 2026-08-06T09:44:54Z | pushed 2026-08-06T09:43:45Z
Lanqd/pentest-notes
我的渗透实验手册 | stars: 0 | forks: 0 | 2026-08-06T10:48:55Z
yuanguin37/GKN-Phantom
GKN-Phantom 是一个面向 OpenClaw AI Agent 框架的工业级自动化渗透测试技能包。v5.0.0 配备 28 个检测模块,覆盖 38 种漏洞类型,支持 25+ 种 WAF 识别与绕过策略,20+ 条攻击链模式,在严格的 Scope Guard · Risk Gate · Rate Limiter 三重安全模型下,执行全生命周期安全验证:从零触碰被动侦察、主动资产发现、分层漏洞检测、交互式浏览器认证、证据验证、攻击路...
galact-byte/galact-Skills
个人自用 Agent Skill 库(SKILL.md 标准),现阶段聚焦授权渗透漏洞挖掘:14 类 hunt-* + 攻击面研判总线,自带静态+靶标端到端测试。后续扩展其它领域。 | topics: agent-skills, security, skill-md, web-security | language: Python | stars: 2 | forks: 0 | updated 2026-08-13T03:27:32Z ...
snowflakeovo/enterprise-automated-pentest-agent
面向授权 Web/API 安全测试的自动化渗透 Agent 控制面 | language: Python | stars: 2 | forks: 0 | updated 2026-08-12T06:47:50Z | pushed 2026-08-07T08:26:28Z
xy200303/webshell-client
一个轻量的 PHP 一句话 Webshell 连接与管理工具,纯 Python 标准库实现,无需安装任何依赖。 面向授权渗透测试与靶场研究场景,除基础的命令执行 / 文件传输外,内置 PHP-FPM bypass 能力:在目标 disable_functions 禁掉全部命令执行函数时,通过直连本机 FPM socket 加载恶意扩展实现绕过 | language: Python | stars: 1 | forks: 0 | upda...
hwkai007/hekai
渗透报告 | stars: 0 | forks: 0 | updated 2026-08-07T10:47:11Z | pushed 2026-08-07T10:45:16Z
Marven11/LinHai
A Multi-Machine control Coding/Hacking Agent, using any `bash` like local machine. | 一个多机器控制编程/渗透Agent, 像操控本机一样操控任意bash | topics: agent, ai, coding, hacking, harness, llm, tui | language: Python | stars: 6 | forks: 0 | u...
Pkkls/sbc-dns-poisoning
Chinese SBCs (Sipeed LicheeRV/MaixCAM) ship GFW-poisoning DNS by default: blocked domains like api.telegram.org resolve to Facebook decoy IPs. Reproduction, detection, remediation. | topics: 114dns, alidns, china, dns-hi...