Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Coff0xc/lobster-guard
OpenClaw Security Assessment Tool | OpenClaw安全评估工具 | 31 Attack Chains | 23 Nuclei Templates | Full RCE Chain | Secret Extraction | Rogue Node | Interactive Shell | Shodan/FOFA Discovery | topics: ai-security, automation,...
cht11/evil-llm-relay
Security research: how a malicious LLM relay service performs zero-click RCE on Claude Code and OpenClaw users via SSE response injection
symphony2colour/fonttools-varlib-cve-2025-66034-rce.py
Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, enabling arbitrary file writes. The script automates payload ...
Shyamkratos/rce_cdp
mehh | language: HTML | homepage: https://rce-cdp.vercel.app
v-jfanca/cve-2026-20833-rc4-kerberos
Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833) | language: PowerShell
MrSmiiith/hg6145f1-full-access
FiberHome HG6145F1 (Algeria Telecom RP4423) — Full admin access, root shell, custom dark WebUI, RCE exploit & 4 CVE submissions. By Smothy / Numb Team | topics: algerie-telecom, cve, fiberhome, firmware, hg6145f1, rce, r...
Rohitberiwala/FontTraverse-Exploit
A Python-based exploit for the VariaType machine on HackTheBox. It leverages a Path Traversal vulnerability in the fontTools library's .designspace file processing to achieve Remote Code Execution (RCE) via a PHP web she...
SnailSploit/CVE-2026-31899
CVE-2026-31899: Exponential DoS via Recursive <use> Element Amplification in CairoSVG (CVSS 7.5 High)
sangrok-jeon/CVE-2023-46604-Analysis
Apache ActiveMQ OpenWire 역직렬화 RCE 취약점 기술 분석
mdshoaibuddinchanda/zombieguard
ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866) | topics: archive-evasion, archive-security, cve-2026-0866, cybersecurity, entropy-analysis, machine-learning, malware-detection, malware-re...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
ecko554-554/capsaicin
🌶️ Detect web vulnerabilities with Capsaicin, the intelligent web fuzzer and WAF hunter designed for Red Team operations. | topics: bugbounty, cybersecurity, directory-scanner, fuzzing, github-config, go, pentesting, rec...
itunified-io/mcp-cloudflare
Cloudflare MCP Server — multi-zone DNS, tunnels, WAF, Zero Trust, security management via Cloudflare API v4 | language: TypeScript | stars: 0 | forks: 1 | updated 2026-03-16T18:57:47Z | pushed 2026-03-16T18:57:58Z
openprx/prx-waf
High-performance Web Application Firewall built on Pingora. OWASP CRS, GeoIP (ip2region), bot detection, API security, and 644+ built-in rules. | topics: api-security, bot-detection, geoip, owasp, pingora, rust, security...
adriansahrudin/super-duper-waffle
stars: 0 | forks: 0 | updated 2026-03-16T19:02:47Z | pushed 2026-03-16T19:02:43Z
sagarbanwa/BountySleuth
rofessional bug bounty companion v3.2. Universal scanner with WAF, CSRF, XSS, DOM Sinks, CORS, Cloud Detection, and Smart Payloads. | language: JavaScript | stars: 1 | forks: 0 | updated 2026-03-16T19:04:41Z | pushed 202...
architmeta/wafa-autoscrapper
Palestine News Agency Auto-Scrapper | language: Jupyter Notebook | stars: 0 | forks: 0 | updated 2026-03-16T19:05:21Z | pushed 2026-03-16T19:05:16Z
sequoia-hope/waffle-iron
language: C++ | stars: 2 | forks: 0 | updated 2026-03-16T19:05:37Z | pushed 2026-03-16T19:05:32Z
duggytuxy/Data-Shield_IPv4_Blocklist
Data-Shield IPv4 Blocklist Community provides an official, curated registry of IPv4 addresses identified as malicious. Updated continuously, this resource offers vital threat intelligence to bolster your Firewall and WAF...
dalia-abdallah25/anyrouter-opencode-bridge
🌉 Bridge AnyRouter with a local proxy to bypass WAF and TLS fingerprint issues, ensuring smooth integration with OpenCode and CherryStudio. | topics: agentrouter, ai, anthropic, check-in, claude-skills, cloudflare-worker...
jm-kyle/WAF
language: HTML | stars: 0 | forks: 0 | updated 2026-03-16T19:08:57Z | pushed 2026-03-16T19:08:52Z | homepage: https://waf-beryl.vercel.app