Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
CCELEND/CVE-2026-40369
CVE-2026-40369本地权限提升漏洞exp | language: C++
daemoncibsec/mcpExec
POC for CVE-2026-23744 for a python revshell | language: Python
limo57640-crypto/wp-user-registration-vuln-checker
Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs. | topics: bash, cve-2026-1492, ioc-scanner, ping7, security-tools, user-registration,...
limo57640-crypto/nginx-rift-detector
Free NGINX Rift CVE-2026-42945 detector for version, rewrite config, ASLR, crash logs, and exploitation indicators. | topics: bash, cve-2026-42945, incident-response, nginx, nginx-rift, ping7, security-tools, vulnerabili...
limo57640-crypto/cpanel-cve-41940-detector
Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs. | topics: bash, cpanel, cve-2026-41940, incident-response, ioc-scanner, ping7, ransom...
87achrafg-stack/CVE-2026-6279.py
CVE-2026-6279 | language: Python
Jenderal92/CVE-2026-8206
Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6). | topics: bug-bounty, cve-2026-8206, exploit, pentesting, security, vulnera...
zycoder0day/CVE-2026-6279
CVE-2026-6279 — Avada Builder <= 3.15.2 Unauthenticated RCE via call_user_func() | language: Python
azilRababe/CVE-2026-42945
Technical analysis of CVE-2026-42945 (NGINX Rift), a critical heap buffer overflow in NGINX's rewrite engine caused by a state mismatch between length calculation and copy operations, enabling worker crashes and potentia...
azilRababe/CVE-2026-46300
Technical analysis of CVE-2026-46300 (Fragnesia), a Linux kernel page-cache write vulnerability that enables local privilege escalation through SKBFL_SHARED_FRAG invariant violations in the networking stack.
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
burpheart/mbtm
攻击流量模拟 用于迷惑蓝队 分散蓝队精力 混淆真实攻击流量 | language: Python | stars: 196 | forks: 21 | updated 2026-03-12T03:05:02Z | pushed 2021-02-25T12:03:08Z
Blue-Team-CN/Attack-traffic-PACPs
攻击流量包,辅助安全运营/分析人员,HVV蓝队工程师开展流量攻击研判工作 | stars: 72 | forks: 12 | updated 2026-07-30T19:10:00Z | pushed 2023-09-07T08:59:28Z
satan1a/awesome-cybersecurity-blueteam-cn
网络安全 · 攻防对抗 · 蓝队清单,中文版 | topics: attack-defense, awesome, blue-team, chinese-translation, cybersecurity | language: HTML | stars: 968 | forks: 120 | updated 2026-09-07T12:54:58Z | pushed 2023-12-03T15:29:38Z | homepage: ...
ChinaRan0/BlueTeamTools
蓝队工具箱 | language: Python | stars: 561 | forks: 29 | updated 2026-09-03T01:20:52Z | pushed 2025-06-22T05:53:07Z
CuriousLearnerDev/TrafficEye
This tool is designed to help penetration testers and network administrators identify potential security threats, especially those targeting web applications such as SQL injection, XSS, and WebShells. Its modular desig 该...
ffffffff0x/1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup | topics: blueteam, collection, ctf, hacking, ics-security, infosec, linux-learning, markdown-article, pentest, pentest-tool, poc, post-penet...
ffffffff0x/f8x
红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool | topics: bash, bash-script, ctf, ctf-tools, ffffffff0x, linux, pentest-tool, shell, vps | language: Shell | stars: 2160 | forks: 291 | updated 2026-09...
abc123info/BlueTeamTools
蓝队分析研判工具箱,功能包括内存马反编译分析、各种代码格式化、网空资产测绘功能、溯源辅助、解密冰蝎流量、解密哥斯拉流量、解密Shiro/CAS/Log4j2的攻击payload、IP/端口连接分析、各种编码/解码功能、蓝队分析常用网址、java反序列化数据包分析、Java类名搜索、Fofa搜索、Hunter搜索等。 | stars: 1874 | forks: 110 | updated 2026-09-08T03:53:13Z | p...
yuvikapoorDFIR/MailItemsAccessed-GUI
The Mail Items Accessed Correlator is a Windows DFIR tool that matches MailItemsAccessed events from Unified Audit Log exports with email metadata from Microsoft Purview Content Search, helping identify which emails a th...
zenmisael/Threat-Hunting
Host-Based EDR + Rootkit Detection + DFIR Tool (Single Binary) | language: Go | stars: 0 | forks: 0 | updated 2026-03-20T04:58:57Z | pushed 2026-03-20T04:58:54Z