Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
bibotai/secveri-cve-2026-50011-positive
language: Java
MoxitPanchal/EverShop-Lab-CVE-2026-25993
language: JavaScript
nabhan-mohy/cve-2026-27483-lab
A containerized enterprise-style lab for researching and defending against CVE-2026-27483. | language: Shell
jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
Proof-of-concept for CVE-2026-43284 — 4-byte XFRM/ESP page-cache write primitive to patch a setuid binary (x86_64, user namespaces). Includes kernel preflight + SUID scan. | language: C
jayhutajulu1/CVE-2026-43494-PinTheft-PoC
Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized research only. | language: C
MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410. | language: Shell
0xBlackash/CVE-2026-15409
CVE-2026-15409 | language: Python
Sana-404/CVE-2026-8388-Mitigation-and-Detection
dfs333/trivysupplychainanalysis
Formally verified, quantitative reconstruction of the Trivy/TeamPCP GitHub Actions supply-chain attack (CVE-2026-33634): a TLA+/TLC incident model, PRISM probabilistic analysis, and a 189-workflow corpus study. | topics:...
babyshen/CVE-2026-57155
OPNsense Root RCE (CVE-2026-57155) | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
lingxiasanshi/web-audit
用于web渗透的小skill | language: Python | stars: 2 | forks: 0 | updated 2026-07-24T09:46:47Z | pushed 2026-07-23T08:55:37Z
yzdily/xuanjian
一个会操作浏览器、会抓包改包、会按照方法论执行、会自己验证漏洞的自动化渗透测试 Agent | language: Python | stars: 8 | forks: 0 | updated 2026-08-18T08:28:35Z | pushed 2026-08-18T08:27:44Z
kuaiyelink/HalberdStrike
HalberdStrike由快页佚名实验室开发,基于PenTestGPT思想,使用大语言模型驱动三模块协作架构实现的端到端自动化渗透测试工具 | language: Python | stars: 3 | forks: 0 | updated 2026-07-25T06:06:57Z | pushed 2026-07-25T06:06:35Z
wnm795/AI-Recon-Agent
AI渗透测试信息收集 Agent,基于 LangGraph 状态驱动工作流,支持自然语言对话和 CLI 直扫。集成被动信息收集、主动扫描、NVD/CVE 向量知识库、漏洞匹配与 Markdown 报告生成,支持环境自检、缓存管理和快速同步 CVE 数据。 | language: Python | stars: 1 | forks: 0 | updated 2026-07-26T07:18:15Z | pushed 2026-07-26T...
wangzifan396-wzf/security-viz-lab
网络安全可视化实验室 - DDoS、SQL注入、XSS/CSRF、渗透测试、WAF、IDS/IPS、蜜罐、零信任 | topics: computer-science, csrf, css, cybersecurity, data-viz, ddos, education, html, interactive, javascript, single-file, software-engineering, sql-injection, s...
shuaiqideyu/SecAtlas
结构化中文网络渗透知识库:技术卡、专题、案例与多 Agent 协作维护 | topics: ai-agents, api-security, application-security, blackmule, chinese, cloud-security, ctf, cybersecurity, cybersecurity-learning, infosec, knowledge-base, network-security, pene...
SilasWu50/WebScanner-with-AI
这是一款接入ai分析的集成信息收集工具,集成了多个主流github上优秀的信息收集工具,并通过ai进行自动化信息整理,精准高效暴露突破口给予渗透人员 | language: Python | stars: 3 | forks: 1 | updated 2026-07-28T00:07:30Z | pushed 2026-07-26T07:12:24Z
YHalo-wyh/AegisCabinet-Zero
校园零信任智能外卖柜攻防仿真系统:Schnorr ZKP、侧信道、重放攻击与固件溢出防护 | topics: cybersecurity-education, iot-security, schnorr, streamlit, zero-trust | language: Python | stars: 0 | forks: 0 | updated 2026-08-14T14:02:15Z | pushed 2026-08-14T14:...
HWBoy-J/AT-D
AT&D 红客攻防系统融合深度学习与大数据分析,提供靶场演练、入侵检测、漏洞扫描等功能,有效防御各类网络攻击,并具备自动漏洞修复、攻击溯源、文件分析等特性 | language: CSS | stars: 1 | forks: 0 | updated 2026-08-09T01:08:25Z | pushed 2026-07-15T17:51:25Z
sxtyxt/tianyan_OS
天衍 OS 是一个面向网络安全攻防一体化的 Rust 裸机操作系统。它采用微内核 + 独立 Capsule 架构,在单一系统内同时集成红队攻击能力、蓝队防御能力、AI 自主决策与 C2 指挥调度,适用于攻防演练、自动化渗透测试、安全研究等场景。 | stars: 0 | forks: 0 | 2026-07-15T20:34:34Z