Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
SneakyNachos/CVE-2026-2766-but-with-wasm
CVE-2026-2766, but with wasm | language: JavaScript
Mluex0/CVE-2026-23744-PoC
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with ...
SneakyNachos/CVE-2026-2764-but-with-wasm
CVE-2026-2764, but with wasm | language: JavaScript
CuteeCat/CVE-2026-9198
CVE-2026-9198利用代码 | language: Python
oopnv70-lab/ghostlock-skeleton-v2
CVE-2026-43499 GhostLock APK 骨架 — 从零开始,仅空项目编译验证 | language: Java
oopnv70-lab/ghostlock-skeleton
CVE-2026-43499 GhostLock APK 骨架 — 仅验证空项目能编译通过
xiaohj233/ghostlock-x200-root
GhostLock-X200 v1.0 - temporary root toolchain for vivo X200 (PD2415 / b57 kernel) based on CVE-2026-43499. For authorized security research only. | language: C
oopnv70-lab/ghostlock-apk
独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行 | language: Java
g0d150ne/XSS2Shell
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control o...
g0d150ne/WP2Shell
WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials. | lan...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
api-evangelist/52toys
52TOYS is a leading IP-driven toy and collectibles company founded in Beijing in 2015 on the brand proposition "Play for Fun." It designs and produces blind boxes, articulated figures, mechanical and model kits, plush, k...
C0nw0nk/Nginx-Lua-Anti-DDoS
A Anti-DDoS script to protect Nginx web servers using Lua with a HTML Javascript based authentication puzzle inspired by Cloudflare I am under attack mode an Anti-DDoS authentication page protect yourself from every atta...
boom5497/yKVwuUSe
2025年网络工程毕设一套(论文+程序源码文件)网络安全测试工具集的设计与实现 关键词:网络安全测试,模块化设计,Python开发,漏洞发现,渗透测试定稿.zip | stars: 1 | forks: 0 | updated 2026-08-18T03:33:41Z | pushed 2026-08-18T03:33:33Z
zhaji2333/ck-finder
基于 pi 的渗透测试 / SRC 漏洞挖掘 Agent:确定性信息收集 + LLM 编排挖洞 + 漏洞复审 + Vue3 Web 指挥台 | topics: agentic-ai, llm-agent, offensive-security, pentest, postgres, recon, src, typescript, vue3, vulnerability-discovery, web-security | language...
moshang174/Automated-penetration-testing-system
基于大模型的自动化渗透测试系统,支持批量漏洞扫描与智能报告生成 | language: Python | stars: 0 | forks: 0 | updated 2026-08-18T19:19:48Z | pushed 2026-08-18T19:12:37Z
hims000/reverse-skill
安全任务技能路由包 — 逆向工程/渗透测试/安全分析(含 ewt360 升学e网通完整逆向) | language: Java | stars: 0 | forks: 0 | updated 2026-08-19T02:54:51Z | pushed 2026-08-19T02:42:24Z
Dest1ny-Sec/Luvv-MCP
Luvv-MCP 是一个 AI 原生的前端安全分析引擎,接入 Claude Code 后,你说一句"帮我审计这个网站",AI 就能自动完成技术栈识别(1.8 万条规则覆盖 CMS/框架/CDN/中间件)、泄露扫描(阿里云 AK、GitHub Token、Webhook、JWT 等 60+ 类敏感信息)、漏洞审计(XSS、开放重定向、CSRF、IDOR、硬编码密码 6 类自动检测)、产品指纹识别(HTTP 响应头/Body/Favicon...
tajleonbennis-maker/chuhaijian_strix
Strix AI 渗透测试报告 - 165.154.226.119 (Supply Chain Security Analyzer) | topics: ai-pentesting, ai-security, cybersecurity, offensive-security, penetration-testing, pentesting, red-teaming, security | language: Python | star...
DK-sky-ice/CyberScurity-of-AI-Jailbreaking
大模型越狱功能包以及一些网络安全工具 | language: Python | stars: 3 | forks: 0 | updated 2026-08-24T06:16:47Z | pushed 2026-08-18T07:22:23Z
zounew1978-pixel/server-tools
绝尘服务器安全工具集 - Fail2ban + iptables 端口管理 | language: Shell | stars: 0 | forks: 0 | updated 2026-09-01T05:14:44Z | pushed 2026-09-01T05:14:30Z