Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
SneakyNachos/CVE-2026-2796-escape-wasm-by-using-wasm
PoC exploit chain for CVE-2026-2796: SpiderMonkey WebAssembly sandbox escape (signature type confusion -> arbitrary R/W -> RCE) | language: JavaScript
Neccie/YellowKey-Bitlocker-CVE-2026-45585
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
BinaryMasc/CVE-2026-46242
aarch64 race condition checker | language: C++
ozcanpng/CVE-2026-76070
Original research and non-destructive PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi | topics: cve, cve-2026-76070, firmware-security, iot-security, nc63, netis, original-researc...
ozcanpng/CVE-2026-76071
Original research and non-destructive PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler | topics: cve, cve-2026-76071, firmware-security, iot-security, nc63, net...
Hika-sec/Terminator_Killer
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver at...
VivianUba/grandstream-cve-2026-2329-analysis
language: Python
0xjohnnydev/CVE-2026-20687-AppleJPEGDriver-UAF
CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC) | topics: apple, arm64, cve-2026-20687, ios, kernel, poc, security, use-after-fre...
K3ysTr0K3R/CVE-2026-39987
CVE-2026-39987 — Marimo Pre-Authentication RCE | topics: exploit, exploitation, marimo, poc, proof-of-concept, rce, rce-exploit, remote-code-execution | language: Python
k0nnect/halo-cve-2026-67919
halo cms plugin 1-request rce from a url, PoC + exploit chain | topics: rce-exploit | language: Python
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
🐚
创建者: s17labs
🛡️
创建者: bmgfl
牧空 Mukong — 自托管、API 优先的个人信息收集与知识管理系统
创建者: virtue192
牧空 Mukong — 自托管、API 优先的个人信息收集与知识管理系统
Zymbol code auditor with Mandarin Chinese identifiers · 用中文标识符构建的 Zymbol 代码审计工具
创建者: zymbol-lang
Zymbol code auditor with Mandarin Chinese identifiers · 用中文标识符构建的 Zymbol 代码审计工具
Easy Scan — 跨平台桌面资产侦察工具:子域名枚举、端口扫描、Web 指纹、截图与漏洞检测
创建者: MoShouSecurity
Easy Scan — 跨平台桌面资产侦察工具:子域名枚举、端口扫描、Web 指纹、截图与漏洞检测
2022计算机毕设一套 终稿 (论文+程序源代码+使用说明)一款支持通过规则扩展进行终端防护对抗的后渗透框架设计与实现_596a004a-efc5-4543-a2ed-82b6a5ad11f5.zip
创建者: pq0khqbiue
2022计算机毕设一套 终稿 (论文+程序源代码+使用说明)一款支持通过规则扩展进行终端防护对抗的后渗透框架设计与实现_596a004a-efc5-4543-a2ed-82b6a5ad11f5.zip
Web Shell
创建者: wushilin
Web Shell
通过编辑器菜单按钮将后缀名为.xlsx或.xls的Excel文件序列化为二进制数据以及对应的容器类和数据结构类,然后通过管理器提供将二进制数据反序列化的方法。
创建者: HK416CYES
通过编辑器菜单按钮将后缀名为.xlsx或.xls的Excel文件序列化为二进制数据以及对应的容器类和数据结构类,然后通过管理器提供将二进制数据反序列化的方法。
Nginx 访问日志安全分析工具 —— 检测常见攻击行为并导出多格式安全报告(Bash + Go 双版本)。 针对 Web 服务器访问日志做离线安全检测:SQL 注入、XSS、路径穿越、命令注入、暴力破解、爬虫、CC 攻击、敏感路径探测等,基于加权威胁评分体系输出高危 IP 告警,并生成 md / html / txt 三种报告与 firewalld 封禁建议脚本。
创建者: pslinux
Nginx 访问日志安全分析工具 —— 检测常见攻击行为并导出多格式安全报告(Bash + Go 双版本)。 针对 Web 服务器访问日志做离线安全检测:SQL 注入、XSS、路径穿越、命令注入、暴力破解、爬虫、CC 攻击、敏感路径探测等,基于加权威胁评分体系输出高危 IP 告警,并生成 md / html / txt 三种报告与 firewalld 封禁建议脚本。
远行星号报错信息收集工具 / Crash report tool for Starsector
创建者: jnxyp
远行星号报错信息收集工具 / Crash report tool for Starsector