Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
codeb0ssx/Ultimate-wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7....
seguridadentrerios/CVE-2026-42533
Vulnerabilidad en NGINX | language: Shell
razureink/cve-2026-41940-cpanel_authbypass_reproduction
CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction | language: Python
razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction
CVE Reproduction: cve-2026-34486-tomcat_encrypt_bypass_reproduction | language: Python
razureink/cve-2026-21509-office_security_bypass_reproduction
CVE Reproduction: cve-2026-21509-office_security_bypass_reproduction | language: Python
razureink/cve-2026-0770-langflow_rce_reproduction
CVE Reproduction: cve-2026-0770-langflow_rce_reproduction | language: Python
vulnquest58/PressVector
PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest | language: Python
ekomsSavior/wp2shell
CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi) | language: Python
onesmiledx/CVE-2026-43499
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
WadesWeaponShed/Check-Point-Trusted-Access-Review
Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around CVE-2026-16232, CVE-2026-62144 , and CVE-2026-62145. This tool is not created o...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Fastjson 1.2.83 远程代码执行漏洞(含漏洞环境与 EXP 利用工具)
创建者: huan-cdm
Fastjson 1.2.83 远程代码执行漏洞(含漏洞环境与 EXP 利用工具)
项目通过关闭 Codex Desktop 中可选的 Codex Micro / Work Louder 设备发现,绕过 Electron 主进程每约 10 秒执行一次的同步 HID 枚举。部分 USB、RGB 外设或硬件管理驱动会让该枚 举长时间阻塞,进而造成 Codex 界面无响应及全系统鼠标、键盘卡顿。该方案只阻止 Codex Micro 探测,不影响普通键鼠和其他 HID 设备
创建者: Ghostapple
项目通过关闭 Codex Desktop 中可选的 Codex Micro / Work Louder 设备发现,绕过 Electron 主进程每约 10 秒执行一次的同步 HID 枚举。部分 USB、RGB 外设或硬件管理驱动会让该枚 举长时间阻塞,进而造成 Codex 界面无响应及全系统鼠标、键盘卡顿。该方案只阻止 Codex Micro 探测,不影响普通键鼠和其他 HID 设备
各类信息收集、技能、MCP
创建者: Hunter-YangZM
各类信息收集、技能、MCP
针对智能渗透测试系统某方面的能力构建的测试集
创建者: zsctest
针对智能渗透测试系统某方面的能力构建的测试集
重要站点信息收集系统:自动化追踪 AI 开源组件与模型公司动态,精准捕获最佳实践,赋能团队技术迭代。
创建者: Coisini-0
重要站点信息收集系统:自动化追踪 AI 开源组件与模型公司动态,精准捕获最佳实践,赋能团队技术迭代。
bbylw/open-weights-manifesto-2026
随着人工智能技术的爆发式演进,全球科技界与政策制定者正面临历史性抉择:判断人工智能领导力的标准,不在于单一公司或机构是否拥有某一个封闭的前沿模型,而在于能否建立一个强大、开放且能渗透至社会各个角落的繁荣生态。 本公开信通过借鉴 20 世纪 80 年代开源软件运动的历史经验,深刻阐明了“开放权重模型 (Open Weights Models)”对于保障国家与机构技术主权、推动经济可持续增长、强化网络国防安全以及维护自由市场竞争的关键作用。...
Wyl-cmd/kxns-cli
一个定制的渗透专属AI代理CLI工具 | language: Python | stars: 3 | forks: 0 | updated 2026-07-28T23:05:54Z | pushed 2026-07-28T23:04:54Z
Autumn-27/ARTEX
AI 自主渗透测试系统 | language: Go | stars: 651 | forks: 95 | updated 2026-09-03T17:47:32Z | pushed 2026-08-31T16:24:54Z | homepage: https://artex-demo.vercel.app
zsctest/Agent-Evaluation
针对智能渗透测试系统某方面的能力构建的测试集 | language: Python | stars: 0 | forks: 0 | updated 2026-07-27T03:30:57Z | pushed 2026-07-27T03:30:50Z
buzhimingdeaikun/Dual-Network-Penetration-Test
基于VMware搭建的双层网络渗透测试靶场环境(DMZ区+服务器区),包含Web漏洞挖掘、内网穿透代理搭建、Metasploit提权及安全告警联动。 | stars: 0 | forks: 0 | updated 2026-07-27T08:53:58Z | pushed 2026-07-27T08:52:48Z