Intelligence Digest
威胁情报
统一威胁情报视图,聚合漏洞监控、网安开源项目与官方源情报
漏洞监控
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
2959总量
网安开源项目
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
1546总量
威胁情报
来自 360、奇安信、斗象等官方站点的公开情报聚合。
235总量
AnggaTechI/Mass-Scanner-CVE-2026-2631
Async mass-checker for authorized internal testing of CVE-2026-2631 exposure. | language: Python
sdsfee557/biyesheji2118
【计算机毕业设计_软赛】基于SpringBoot+Vue的java基于云平台的信息安全攻防实训平台【毕业设计源码 毕业设计论文 毕业设计完整项目 可运行 二次开发 前后端 毕业设计、本科毕业设计、毕业设计源码、毕业设计论文、java 毕业设计、springboot 毕业设计、vue 毕业设计、wms、仓储管理系统、仓库管理系统、智能仓储、物流管理系统、库存管理、出入库管理、供应链管理、springboot、vue、vue3、elemen...
ISC Stormcast For Friday, March 13th, 2026 https://isc.sans.edu/podcastdetail/9848, (Fri, Mar 13th)
dinosn/ghost-cve-2026-26980
CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering) | language: Python
hjdski/biyesheji2118
【计算机毕业设计_软赛】基于SpringBoot+Vue的java基于云平台的信息安全攻防实训平台【毕业设计源码 毕业设计论文 毕业设计完整项目 可运行 二次开发 前后端 毕业设计、本科毕业设计、毕业设计源码、毕业设计论文、java 毕业设计、springboot 毕业设计、vue 毕业设计、wms、仓储管理系统、仓库管理系统、智能仓储、物流管理系统、库存管理、出入库管理、供应链管理、springboot、vue、vue3、elemen...
每日安全动态推送(26/3/12)
Vim NFA 正则引擎中 NULL 指针解引用漏洞;Perplexity Comet 浏览器零点击漏洞事件;Check Point揭露Anthropic日前修補的Claude Code漏洞
Penguinsecq/CVE-2026-6355
Exploit PoC of CVE-2026-6356
hangxin1940/PenetrationTestClaw
基于OpenClaw的渗透测试框架 | language: Python | stars: 1 | forks: 0 | updated 2026-04-02T21:25:06Z | pushed 2026-03-31T13:31:30Z
完整分析 | 首个被捕获的利用OpenClaw黑产团伙
ClickFix攻击在大模型时代的演变
Shreda/CVE-2026-33032-nginx-ui-vuln-lab
Docker Compose setup to demonstrate the nginx-ui missing authentication vulnerability | language: Python
linkzh1/
基于python的智能家居物联网设备漏洞扫描工具 | language: Python | stars: 0 | forks: 0 | updated 2026-03-31T12:35:27Z | pushed 2026-03-31T12:35:22Z
ISC Stormcast For Thursday, March 12th, 2026 https://isc.sans.edu/podcastdetail/9846, (Thu, Mar 12th)
keraattin/CVE-2026-39842
Critical remote code execution vulnerability in OpenRemote's Rules Engine allows authenticated users with `write:rules` role to execute arbitrary code on the server with root privileges. | language: Python
heheh214/biyesheji2118
【计算机毕业设计_软赛】基于SpringBoot+Vue的java基于云平台的信息安全攻防实训平台【毕业设计源码 毕业设计论文 毕业设计完整项目 可运行 二次开发 前后端 毕业设计、本科毕业设计、毕业设计源码、毕业设计论文、java 毕业设计、springboot 毕业设计、vue 毕业设计、wms、仓储管理系统、仓库管理系统、智能仓储、物流管理系统、库存管理、出入库管理、供应链管理、springboot、vue、vue3、elemen...
When your IoT Device Logs in as Admin, It?s too Late! [Guest Diary], (Wed, Mar 11th)
[This is a Guest Diary by Adam Thorman, an ISC intern as part of the SANS.edu BACS program]
Chromium: CVE-2026-6307 Type Confusion in Turbofan
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
psp123123/fleetpilots
自动化渗透测试平台 | stars: 0 | forks: 0 | updated 2026-03-31T11:39:36Z | pushed 2026-03-31T11:39:25Z
当心“龙虾”变“毒蝎”:你在GitHub上领的“龙虾”可能有毒!
奇安信威胁情报中心红雨滴团队私有情报系统监测到大量仿冒OpenClaw的安装站点正在借机投毒。在一众常见的木马中,我们发现一个“另类”——它携带着俄语调试字符串,投递的是一款前所未见的恶意软件。因其调试字符串,我们将其命名为 “Anti-bot”。
Chromium: CVE-2026-6306 Heap buffer overflow in PDFium
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
78778443/QingScan
一个漏洞扫描器粘合剂,添加目标后30款工具自动调用;支持 web扫描、系统扫描、子域名收集、目录扫描、主机扫描、主机发现、组件识别、URL爬虫、XRAY扫描、AWVS自动扫描、POC批量验证,SSH批量测试、vulmap。 | language: PHP | stars: 1829 | forks: 295 | updated 2026-04-19T02:04:56Z | pushed 2026-04-03T06:18:06Z
Analyzing "Zombie Zip" Files (CVE-2026-0866), (Wed, Mar 11th)
A new vulnerability (CVE-2026-0866) has been published: Zombie Zip.
Chromium: CVE-2026-6305 Heap buffer overflow in PDFium
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
zzzjiushi/web_scanner
一个轻量级模块化 Web 漏洞扫描器(DAST),实现了 SQL 注入,XSS,命令注入等诸多漏洞的 自动化检测,具备可扩展的插件化架构。 | language: Python | stars: 0 | forks: 0 | updated 2026-04-06T09:46:03Z | pushed 2026-04-06T09:45:59Z
ISC Stormcast For Wednesday, March 11th, 2026 https://isc.sans.edu/podcastdetail/9844, (Wed, Mar 11th)
Chromium: CVE-2026-6304 Use after free in Graphite
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
Kayoko-oni/AirCombat
AirCombat是一个基于Open3D的无人机集群攻防仿真系统,实现雷达/侦察视野下的自动对抗与策略规划。 | language: Python | stars: 1 | forks: 0 | updated 2026-04-27T07:44:09Z | pushed 2026-04-27T07:44:05Z
Microsoft Patch Tuesday March 2026, (Tue, Mar 10th)
Microsoft today released patches for 93 vulnerabilities, including 9 vulnerabilities in Chromium affecting Microsoft Edge. 8 of the vulnerabilities are rated critical. 2 were disclosed prior to today but have not yet bee...
Chromium: CVE-2026-6303 Use after free in Codecs
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2026">Google Chrome Releases</a> for mo...
maoxianjia98/-Python
一个基于Python的网络异常流量分析和漏洞扫描的系统开发 | language: HTML | stars: 0 | forks: 0 | updated 2026-03-31T07:48:10Z | pushed 2026-03-31T07:48:06Z
每日安全动态推送(26/3/10)
利用跨层身份去同步性的新型Wi-Fi攻击;Signal 被学术界视为即时通讯应用的“黄金标准”,本文提出了两个实用攻击;通过WiFi信号映射人体关键点实现穿透墙壁的人体活动识别