Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
osamaloay/navigate-cms-rce
metasploit RCE code for navigate cms portal for php written in python | language: Python
Skynoxk/CVE-2026-27944
Automated exploit script for CVE-2026-27944 (Nginx UI). Downloads/decrypts backups, extracts system secrets, and creates rogue admin accounts for full dashboard access. | language: Python
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, an
CVE-2026-1948;50d4e3dfe52fcb28e65fc7878d982a08;The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactiva...
Version 1.6.1 of the Flash Payments package graphql-upload-minimal is vulnerable to prototype pollution. This vulnerability, located in the processRequest() function, allows an attacker to inject special property names i
CVE-2025-65587;a1cfbab742f640d3c0d253218b3593a8;Version 1.6.1 of the Flash Payments package graphql-upload-minimal is vulnerable to prototype pollution. This vulnerability, located in the processRequest() function, allow...
Skynoxk/CVE-2026-27944-POC
language: Python
danaug23/detect_CVE-2026-25177
Production-safe scanner that detects CVE-2026-25177 (AD SPN Unicode Collision) exploitation on Active Directory Domain Controllers. Read-only. | language: Python
Chromium: CVE-2026-3910 Inappropriate implementation in V8
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2021">Google Chrome Releases</a> for mo...
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-0385;beaa6c5c1ad6e34de6adb3cddb0d60f0
Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The com
CVE-2026-32732;e21b852e448a11eeedefc9496d0bd901;Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS ex...
Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a
CVE-2026-32729;9f86646d1045626bc170acbcd9169c4b;Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account l...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
da1csb/Daniyal-Almetayev-Portfolio
SOC Analyst portfolio featuring SIEM, threat hunting, web pentest, and malware analysis projects | stars: 0 | forks: 0 | updated 2026-03-16T11:56:50Z | pushed 2026-03-16T11:56:47Z
Herimnx/Phantom-Dropper-WebBased-Chrome-Bypas-Fud-Runtime-Native
Trojan builders focus on creating hidden malware with downloader and encryption capabilities. Assembly changers and mutex features ensure uniqueness, while RAT clients provide remote access to infected systems. | topics:...
Denisapti/CYBERTRACKER
Group project making a malware scanner | language: Python | stars: 0 | forks: 0 | updated 2026-03-16T12:01:05Z | pushed 2026-03-16T12:01:02Z
markBH1510/Threat-Hunting-Reports
A collection of threat hunting reports based on MITRE ATT&CK framework, covering malware TTPs, detection logic, and IOCs. | topics: apt37, blue-team, dfir, ioc, malware-analysis, mitre-attack, soc, splunk, threat-hunting...
cybersecurity-dev/awesome-malware-analysis-resources
Awesome Malware Analysis Resources | topics: awesome, awesome-list, awesome-lists, malware-analysis-resource, malware-analysis-resources | stars: 1 | forks: 0 | updated 2026-03-16T12:14:31Z | pushed 2026-03-16T12:14:28Z
abdowwmaksoood1000-blip/Research-on-ShadowLink
I made a research on ShadowLink malware found in a malicious place | stars: 0 | forks: 0 | updated 2026-03-16T12:17:13Z | pushed 2026-03-16T12:17:08Z
Gayathri-Jayan/Malware_detection
language: Python | stars: 0 | forks: 0 | updated 2026-03-16T12:19:24Z | pushed 2026-03-16T12:19:20Z
bastiaan365/dns-security-setup
Secure DNS configuration with Unbound: DNS-over-TLS, DNSSEC validation, blocklists for ads/malware/trackers. Privacy-first DNS for OPNsense or standalone. | topics: blocklist, dns, dns-over-tls, dnssec, opnsense, privacy...
Rackedydig/string_decode_algorithm_apt16
Python script that decodes the strings from APT 16 malware samples | language: Python | stars: 1 | forks: 1 | updated 2026-03-16T12:23:45Z | pushed 2026-03-16T12:23:42Z
Chintan2604/forensic
Conteneur Docker tout-en-un pour l'investigation numérique, incluant des outils préinstallés pour l'analyse forensique de disques, mémoire, malwares et appareils mobiles. | topics: alerting, awesome, cyber-security, cybe...