Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Baba01hacker666/CVE-2026-23111
Linux Kernel nf_tables Use-After-Free (CVE-2026-23111) — LPE PoC | language: C
orinimron123/CVE-2026-40369-EXPLOIT
Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox | language: C++
V0IDNETWORK/CVE-2026-46331
pedit COW | language: C++
thecodeb0ss/CVE-2026-55488
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read | topics: codeb0ss, cve-2026-55488, cve-2026-55488-poc, motioneye, realcodeb0ss, thecodeb0ss, uncodeboss | homepage: https://t.me/thec...
derekpreston81/CVE_ADC_IOC_2026
Citrix NetScaler CVE Preconditions Checker as per CTX696604 | Supported CVE : CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 | language: Python | homepage: https://derekpr...
BiiTts/CVE-2026-58138-Conductor-Unauth-RCE
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root). | topics: conductor, cve-2026-58138, graalvm, java, orkes, poc, rce, securi...
BiiTts/CVE-2026-44789-n8n-PrototypePollution-RCE
CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified e2e. | topics: cve-2026-44789, n8n, nodejs, poc, prototype-pollution, rc...
BiiTts/CVE-2026-46490-samlify-SAML-Attribute-Injection
CVE-2026-46490 — samlify <2.13.0 SAML AttributeValue XML injection -> signed-assertion privilege escalation. Self-contained PoC, verified e2e. | topics: cve-2026-46490, nodejs, poc, privilege-escalation, saml, samlify, s...
JohannesLks/CVE-2026-33186
gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass) | topics: cve, exploit, security, vulnerability | language: Python
JohannesLks/CVE-2026-27654
NGINX `ngx_http_dav_module` Heap Buffer Overflow via `size_t` Underflow (Remote DoS / Potential RCE) | topics: cve, exploit, security, vulnerability | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
Yamato-Security/suzaku
Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs. | topics: aws, azure, cloudtrail, detection, dfir, engineering, entra, forensics, gcp, hunting, id, incident, log, monitor...
killex007-pftw/blue-team-writeups
Blue Team writeups covering SOC alerts, Incident Response, Threat Hunting and Malware Analysis — LetsDefend & HackTheBox. Built as part of my cybersecurity portfolio. | topics: blue-team, cybersecurity, dfir, hackthebox,...
BadSamuraiDev/bs-lists
Cybersecurity lists of TLDs, domains and URLs for threat hunting and posture policy (warn or block) | topics: blocklist, blocklists, browsers, cybersecurity, file-list, infosec, list, lists, lots, pastebin, phishing, rmm...
Reinhard1268/threat-hunting-platform
language: Python | stars: 1 | forks: 0 | updated 2026-03-20T14:19:10Z | pushed 2026-03-20T14:18:04Z
paladin316/ThreatHunting
This repo is where I store my Threat Hunting ideas/content | stars: 89 | forks: 17 | updated 2026-03-20T14:46:08Z | pushed 2026-03-20T14:41:37Z
sand5066/Threat-Hunting-IOCs
stars: 4 | forks: 1 | updated 2026-03-20T14:49:03Z | pushed 2026-03-20T14:48:57Z
steven-dah/PySecurity
PySecurity is a threat hunting tool that uses various APIs to identify different attack vectors and compromise methods. | language: Python | stars: 0 | forks: 0 | updated 2026-03-20T15:49:56Z | pushed 2026-03-20T15:49:53...
chandraktrivedi/PurpleHawkS
PurpleHawkS aims to delivers high-fidelity Cyber Attack-Defense intelligence designed to strengthen organizational resilience. We provide the insights necessary to execute data-driven Purple Teaming, launch proactive Thr...
MalbinGerorge/threat-hunting-case-studies
stars: 0 | forks: 0 | updated 2026-03-20T16:29:04Z | pushed 2026-03-20T16:29:01Z
shane-rubrik/GenerateThreatFile
A PowerShell-based security simulator designed to test Rubrik Security Cloud (RSC) Threat Hunting. Safely generates harmless, randomized PE files, simulates lateral movement across network shares, and automates RSC Threa...