Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
minq0x1412/CVE-2026-21955
language: C
JFOZ1010/CVE-2026-14871
BOLA/IDOR vulnerability in osTicket ajax.tickets.php | Responsible Disclosure | language: Python
Ch4120N/CVE-2026-58138
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root). | topics: bug-bounty, code-injection, conductor, cve-2026-58138, cwe-94, cy...
shinthink/CVE-2026-13001
Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8 | topics: 0day, cve, exploit, file-upload, pentest, podlove, security, vulnerability, wordpress | l...
oscerd/CVE-2026-46591
Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization bypass / cross-label data exfiltration (fixed in 4.14.8/4.18.3/4.21.0) | to...
FzRsLLaSheR/CVE-2026-14960-CVE-2026-14961
ndouglas-cloudsmith/CVE-2026-53359
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerability in the KVM code that has been sitting there since 2010.
repo-ranger21/security-portfolio-chris-peterson
My portfolio showcasing vulnerability research (CVE-2026-11989, CVE-2026-11395) and automated threat orchestration engineering (Lucius Engine, TalonVigil).
seqra/cve-2026-58138
language: Python
lamaper/CVE-2026-52199
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
sxtyxt/tianyan_OS
天衍 OS 是一个面向网络安全攻防一体化的 Rust 裸机操作系统。它采用微内核 + 独立 Capsule 架构,在单一系统内同时集成红队攻击能力、蓝队防御能力、AI 自主决策与 C2 指挥调度,适用于攻防演练、自动化渗透测试、安全研究等场景。 | stars: 0 | forks: 0 | 2026-07-15T20:34:34Z
MWDLH/Full-stack-cybersecurity-expert
AI Agent 全栈安全协议 — 非提示词,而是一套可执行的攻防规范。红/蓝/审计/咨询四模式切换,含状态管理(断点续传)、Token 斩断、防幻觉自检、11 类操作安全红线。15 平台场景覆盖 AD/云/移动。 | language: Markdown | stars: 2 | forks: 0 | updated 2026-07-29T01:59:06Z | pushed 2026-07-16T01:36:05Z
kookisky/jinghuacheng
京華城案15場言詞辯論逐字稿與分析|檢辯攻防完整紀錄 | topics: court-debate, jinghuacheng, ke-wenzhe, taiwan-judiciary, transcript | language: HTML | stars: 0 | forks: 0 | updated 2026-07-16T07:20:24Z | pushed 2026-07-16T07:51:40Z | homepage: htt...
Fenguopeng/dropsec-blog
中原工学院 DROPS 攻防实验室技术博客 | language: Dockerfile | stars: 0 | forks: 0 | updated 2026-07-16T08:44:33Z | pushed 2026-07-16T08:44:15Z | homepage: https://fenguopeng.github.io/dropsec-blog/
createmeow/basecore
一个适用于多人大型服务器Minecraft模组,添加了基地攻防玩法 | language: Java | stars: 1 | forks: 0 | updated 2026-08-25T10:25:16Z | pushed 2026-08-25T10:37:25Z
Gnomeshgh0714/pm-team-skill
多Agent产品经理团队协作流程Skill - 6阶段评审攻防+决策留痕,附可交互 Playbook(扮演总监裁决真实战例) | language: TypeScript | stars: 0 | forks: 0 | updated 2026-08-28T03:35:31Z | pushed 2026-08-28T03:34:56Z
genius1h/web-security-lab
「Web安全学习笔记与漏洞攻防手册,含 SQL注入/XSS/CSRF/SSRF/文件上传/命令注入 6类漏洞的复现、检测与防御方案。」 | language: Python | stars: 0 | forks: 0 | updated 2026-07-20T11:36:07Z | pushed 2026-07-20T11:35:17Z
HangCRH/Counter-Flow
一款极简的多阵营调度战棋游戏。通过拖拽连线下达行军命令,AI 对手会自主进攻防守。核心玩法依赖“行军途中的碰撞抵消”,玩的是心理博弈和兵力算计。 | language: JavaScript | stars: 0 | forks: 0 | updated 2026-07-22T05:40:21Z | pushed 2026-07-22T05:39:30Z
athena-caixinying/debate-prep
华语辩论全流程 Agent Skill:辩题诊断、四辩位准备、模拟攻防、证据核查与复盘。 | topics: agent-skills, chinese-debate, codex, debate, debate-preparation | language: Python | stars: 2 | forks: 0 | updated 2026-07-22T12:29:50Z | pushed 2026-07-22T12:27:24Z
i-am-xjizhi/TraceHarvest
潜影【TraceHarvest】是一款面向网络安全攻防演练场景的自动化信息收集工具。它通过智能化的多引擎搜索和敏感信息提取技术,解决了在大规模目标侦察过程中人工搜索效率低下、信息遗漏严重、重复工作繁多的核心痛点。 | stars: 55 | forks: 2 | updated 2026-08-27T01:45:23Z | pushed 2026-07-29T07:44:32Z