Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
csinexus/mcpshield
Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family) | language: Python
mhtsec/CVE-2026-63030
WordPress 未授权RCE EXP | CVE-2026-63030 | language: Python
ctn-Qvo/CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN
CVE-2026-0073-Android-ADBD-bypass-POC汉化版 | language: Python
K3ysTr0K3R/CVE-2026-34197
CVE-2026-34197 - Apache ActiveMQ Jolokia Remote Code Execution (RCE) | topics: activemq, cve-2026-34197, exploit, exploitation, rce, rce-exploit, remote-code-execution | language: Python
AlMarWorld/KerberosAudit-PS
Kerberos audit for CVE-2026-20833 | language: PowerShell
KuniNogu/drupal-openai-provider-ssrf-cve-2026-13233
CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2. | topics: ai-security, appsec, cv...
qianlijaingshan/n8n-cve-2026-21858
CVE-2026-21858 + CVE-2025-68613 — n8n unauthenticated file read to RCE exploit | language: Python
Ghalendar/CVE-2026-27971_POC
CVE-2026-27971 qwik rce | language: Python
GhostInExile/CVE-2026-63030-Wp2Shell
WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137) | topics: cve-2026-63030, poc, proof-of-concept, sql-injection, wordpress-rce, wp2shell, wp2shell-exploit, wp2shell-poc | language: Python | homepage: ...
Lutfifakee-Project/wp2shell
wp2shell - WordPress CVE-2026-63030 Exploit & Scanner | topics: cve-2026-63030, exploit, python, rce, security-tools, sql-injection, unauthenticated, unauthenticated-rce, vulnerability-scanner, wordpress, wp2shell, wp2sh...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
漏洞更新
创建者: xiaoqi20231006
漏洞更新
Java 内存马自动化排查程序。上机后一条命令即可完成 Java 进程 / Agent 排查、磁盘注入器扫描、配置篡改检查、网络连接分析、JVM 运行时检测、 日志分析与持久化排查,输出带风险等级的排查报告。
创建者: xiaoxin2016
Java 内存马自动化排查程序。上机后一条命令即可完成 Java 进程 / Agent 排查、磁盘注入器扫描、配置篡改检查、网络连接分析、JVM 运行时检测、 日志分析与持久化排查,输出带风险等级的排查报告。
Catch what AI missed — real-time security for AI-generated code. Detects hallucinated packages, missing security & AI pattern errors. | AI VibeCoding 安全检测插件 — 检测幻觉依赖包、缺失安全措施、AI 常见错误模式,在 AI 生成代码时拦住漏洞。
创建者: Unclecheng-li
Catch what AI missed — real-time security for AI-generated code. Detects hallucinated packages, missing security & AI pattern errors. | AI VibeCoding 安全检测插件 — 检测幻觉依赖包、缺失安全措施、AI 常见错误模式,在 AI 生成代码时拦住漏洞。
使用Hermes AI團隊分析web code並找出對應系統漏洞全紀錄(hermes-ai-web-vuln-analysis)
创建者: jash-git
使用Hermes AI團隊分析web code並找出對應系統漏洞全紀錄(hermes-ai-web-vuln-analysis)
存储桶遍历漏洞利用工具
创建者: jdr2021
存储桶遍历漏洞利用工具
基于贝叶斯网络的网络安全态势感知研判平台,前后端分离 Vue3+FastAPI 项目
创建者: Lhb-dot
基于贝叶斯网络的网络安全态势感知研判平台,前后端分离 Vue3+FastAPI 项目
Blue-team DFIR platform for PCAP triage - YARA scanning, protocol-state attack detection, C2/webshell/miner hunting, GeoIP mapping, and AI-assisted analysis.
创建者: geezsecurity
Blue-team DFIR platform for PCAP triage - YARA scanning, protocol-state attack detection, C2/webshell/miner hunting, GeoIP mapping, and AI-assisted analysis.
opentitan漏洞测试工具
创建者: ttt1016
opentitan漏洞测试工具
🛡️
创建者: web3-ai-game
这是一个关于vulhub所有漏洞复现的文档
创建者: Charing-Men
这是一个关于vulhub所有漏洞复现的文档