Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
0xBlackash/CVE-2026-8451
CVE-2026-8451 | language: Ruby
frada321/asdsadsadasdasdsadsad
CVE-2026-49049 - Unauthenticated File Deletion, Arbitrary Write & XSS Injection for Helix3 Joomla Extension
portbuster1337/CVE-2026-27771
CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication | topics: container-registry, cve, cve-2026-27771, exploit, forgejo, gitea, security, vulne...
willygailo/CVE-2026-41940-Linux
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible fo...
BimaBalance/Cve-2026-27944-Tools-Exploit
Suka suka lah | language: Python
1beelze/CVE-2026-23550
language: Python
mooder1/dirtyclone-CVE-2026-43503
language: Python
tematemaru/CVE-2026-31431-simple-test
language: C
canyie/TransitionPlayer
CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb | language: Java
Sch8ill/CVE-2026-31309
Improper Access Control in Mysterium Node before v1.36.0 | homepage: https://cve.org/CVERecord?id=CVE-2026-31309
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
atreasureboy/ovogo
Ovogo: Autonomous Red Team Coordination Engine. 基于 AI Agent 的自动化渗透测试与红队协同引擎(专为靶场环境设计),支持 MITRE ATT&CK 攻击链生成、多节点并行利用与 Flag 自动化收集。 | topics: ai-agent, automated-security, ctf-solver, cyber-range, langgraph, llm-security, m...
gmeier909/bface-agent
bface-agent是一个由ClaudeCode驱动的红队渗透工具。 | language: Go | stars: 15 | forks: 1 | updated 2026-09-07T06:19:32Z | pushed 2026-08-26T04:12:28Z
Amilan314/NCRT
一个集成化越狱红队测试平台 | language: Python | stars: 0 | forks: 1 | updated 2026-07-02T11:21:25Z | pushed 2026-07-02T11:21:20Z
Dest1ny-Sec/DesJsFinder
被动JS分析 + 框架识别 + 主动Fuzz + 响应指纹 — 红队API挖掘利器 | topics: browser-extension, fingerprint, fuzzing, javascript, js-analysis, pentest, red-team, security | language: JavaScript | stars: 130 | forks: 9 | updated 2026-09-02T04:21:...
icecliffs/nextanti
NextAnti is a browser extension focused on anti-honeypot and anti anti-honeypot techniques, NextAnti 是一款专门用于浏览器反蜜罐反反蜜罐(Anti-Honeypot)的插件,自动阻断蜜罐请求,被蜜罐溯源,皆在于快速被蓝队识破并反制红队小伎俩 | topics: anti, antihonypot, attack-defense, blue...
PuppetWen/RedScope-AI
RedScope AI 是一个面向安全团队、渗透测试、资产侦察、威胁追踪和红队编排的 AI CLI。它基于 Bun、TypeScript、React/Ink 和 MCP 工具生态构建,提供交互式终端助手、非交互式管道模式、多模型 Provider、插件系统、远程控制服务和一套受控的安全工作流脚本 | language: TypeScript | stars: 97 | forks: 19 | updated 2026-07-30T11:...
shangdi-w/-skills
Hermes Agent 红队技能库 | 全平台反编译(18类) + 免杀对抗(18章入门到专家) | 仅供授权安全测试使用 | topics: av-evasion, decompile, hermes-agent, pentesting, redteam, reverse-engineering, security | stars: 6 | forks: 1 | updated 2026-07-08T02:21:43Z | push...
guaidao2/xuanmu-smart-malware-detect
玄幕安全团队自设计架构的智能杀毒软件引擎,由于是在Linux中训练,尚未开发Windows版本的界面,后续添加。(该项目不仅可以查杀木马,还可以让红队来测试自己的免杀能力) | language: Python | stars: 5 | forks: 0 | updated 2026-08-20T02:45:16Z | pushed 2026-08-12T09:29:41Z
Aurelius-zenon/redteam-rs-llm
redteam-rs 是一个面向大语言模型内容安全评测的红队测试框架,提供 CLI 与桌面端两种使用方式。它采用三层表征级越狱架构:L1 探测、L2 牵引、L3 突破,用于系统性地评估模型在安全对齐、越狱防护和提示注入场景下的表现。 | language: Rust | stars: 1 | forks: 0 | updated 2026-07-04T09:00:03Z | pushed 2026-07-04T08:59:20Z
Yn8rt/DDDD-DL
重构DDDD,与DLDL联动快速实现POC与指纹的结合,提高红队资产发现与打点效率 | stars: 58 | forks: 3 | updated 2026-08-21T07:07:55Z | pushed 2026-07-24T06:59:58Z