Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Chromium: CVE-2026-15128 Inappropriate implementation in Forms
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15127 Inappropriate implementation in WebGL
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15126 Use after free in Forms
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15125 Inappropriate implementation in Forms
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15124 Insufficient policy enforcement in Passwords
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15123 Insufficient data validation in DOM
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15121 Use after free in WebRTC
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15122 Insufficient validation of untrusted input in Codecs
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15120 Use after free in Core
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Chromium: CVE-2026-15119 Inappropriate implementation in GetUserMedia
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
RedNexus(赤枢)是一个控制平面型红队多智能体平台,负责把授权项目、智能体调度、Sandbox 执行、结构化证据和攻击路径记录连接起来。它适用于授权渗透测试、资产梳理、漏洞筛选、漏 洞验证、代码审计和安全研究。
创建者: ZunSir
RedNexus(赤枢)是一个控制平面型红队多智能体平台,负责把授权项目、智能体调度、Sandbox 执行、结构化证据和攻击路径记录连接起来。它适用于授权渗透测试、资产梳理、漏洞筛选、漏 洞验证、代码审计和安全研究。
PortSentinel 是一款 Windows 平台网络端口扫描与安全监控工具。项目基于 Python + PyQt5 构建,通过 ctypes 调用 Windows 原生 API(iphlpapi.dll),实现对网络端口的深度扫描、活动连接监控、异常连接关闭以及漏洞风险识别等功能。 项目以 GPL v3 协议开源,遵循 GitHub 标准项目结构,旨在为个人用户与安全研究人员提供一款轻量、可扩展、可视化的本机网络安全审计工具。
创建者: donoot
PortSentinel 是一款 Windows 平台网络端口扫描与安全监控工具。项目基于 Python + PyQt5 构建,通过 ctypes 调用 Windows 原生 API(iphlpapi.dll),实现对网络端口的深度扫描、活动连接监控、异常连接关闭以及漏洞风险识别等功能。 项目以 GPL v3 协议开源,遵循 GitHub 标准项目结构,旨在为个人用户与安全研究人员提供一款轻量、可扩展、可视化的...
煋鉴 Xinpect - AI代码审查专家 | 8大脑并行 × 3027条规则 × 三层防幻觉体系。不是又一个 linter——是 AI 原生代码质检引擎。单次扫描 60 维度并发,从安全漏洞、性能陷阱到架构腐化全链路拦截。免费开源 Brain 1-3,专业版 8 大脑全开。
创建者: HDY-Ezio
煋鉴 Xinpect - AI代码审查专家 | 8大脑并行 × 3027条规则 × 三层防幻觉体系。不是又一个 linter——是 AI 原生代码质检引擎。单次扫描 60 维度并发,从安全漏洞、性能陷阱到架构腐化全链路拦截。免费开源 Brain 1-3,专业版 8 大脑全开。
Agnes AI — OpenHarmony Nday 漏洞自主挖掘系统 (双 LLM Agent ReAct 架构 + Web UI 交互界面)
创建者: Cimen101
Agnes AI — OpenHarmony Nday 漏洞自主挖掘系统 (双 LLM Agent ReAct 架构 + Web UI 交互界面)
自动化一体渗透测试平台:AI 驱动的证据驱动渗透测试平台(融合 vulnflow / vero / AutoRedTeam 三项目为单一代码库,含攻击图、HITL 人工审批、AI/MCP 自审与四格式报告)
创建者: gutddts
自动化一体渗透测试平台:AI 驱动的证据驱动渗透测试平台(融合 vulnflow / vero / AutoRedTeam 三项目为单一代码库,含攻击图、HITL 人工审批、AI/MCP 自审与四格式报告)
漏洞说明
创建者: pipiyyb
漏洞说明
基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 系统级提示词 + 13 个专项安全测试 Skill 知识库
创建者: zhaji2333
基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 系统级提示词 + 13 个专项安全测试 Skill 知识库
vuln_hunter: 漏洞挖掘技能集合(vuln_verify + high_risk_identifier)
创建者: gcf0082
vuln_hunter: 漏洞挖掘技能集合(vuln_verify + high_risk_identifier)
burpsuite渗透ai分析工具(未完成)
创建者: oldzed
burpsuite渗透ai分析工具(未完成)
a codex codexJalibreak,一个codex的破甲方法,无法绕过云端审查,可以降低拒绝率。
创建者: chchch1233
a codex codexJalibreak,一个codex的破甲方法,无法绕过云端审查,可以降低拒绝率。