📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: Nacos-QVD-2026-59388
👤 项目作者: Xxh-v
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 09:44:23

📝 项目描述:
Nacos 未授权管理员账号创建漏洞复现

🔗 点击访问项目地址 GitHub - Xxh-v/Nacos-QVD-2026-59388: Nacos 未授权管理员账号创建漏洞复现
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: phantom-xss
👤 项目作者: kishwordulal2005
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 10:01:14

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - kishwordulal2005/phantom-xss
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-23751-poc
👤 项目作者: SieBRUM
🛠 开发语言: C#
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 09:31:43

📝 项目描述:
Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)

🔗 点击访问项目地址 GitHub - SieBRUM/CVE-2026-23751-poc: Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #CVE

📦 项目名称: fastjson-cve
👤 项目作者: ipisav
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 08:42:04

📝 项目描述:
fastjson-cve-2026-16723

🔗 点击访问项目地址 ipisav/fastjson-cve
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: xss-csrf-test-browser-extension
👤 项目作者: abkr020
🛠 开发语言: CSS
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 08:37:13

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - abkr020/xss-csrf-test-browser-extension
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: htb-labs-cohort
👤 项目作者: DiegoRivas1
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 06:31:06

📝 项目描述:
Hack The Box Cohort walkthrough featuring SSRF filter bypass, internal service discovery, Marimo WebSocket RCE, and PackageKit privilege escalation.

🔗 点击访问项目地址 GitHub - DiegoRivas1/htb-labs-cohort: Hack The Box Cohort walkthrough featuring SSRF filter bypass, internal service discovery…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SecureCode-AI
👤 项目作者: kartikgarg146
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 07:36:14

📝 项目描述:
AI-powered code vulnerability scanner with Gemini AI secure rewrites, risk scoring, and professional PDF security reports.

🔗 点击访问项目地址 GitHub - kartikgarg146/SecureCode-AI: AI-powered code vulnerability scanner with Gemini AI secure rewrites, risk scoring, and professional…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: grype
👤 项目作者: x-cmd-install
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 06:10:01

📝 项目描述:
A vulnerability scanner for container images and filesystems

🔗 点击访问项目地址 GitHub - x-cmd-install/grype: A vulnerability scanner for container images and filesystems
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: osv-scanner
👤 项目作者: x-cmd-install
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 06:18:34

📝 项目描述:
Vulnerability scanner written in Go which uses the data provided by https://osv.dev

🔗 点击访问项目地址 GitHub - x-cmd-install/osv-scanner: Vulnerability scanner written in Go which uses the data provided by https://osv.dev
🚨 GitHub 监控消息提醒

🚨 发现关键词: #内网渗透 #横向移动 #域控

📦 项目名称: biohazard-ctf
👤 项目作者: lilili9646464
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 02:36:41

📝 项目描述:
🧪 BioHazard CTF Lab - 生化公司内网渗透实训靶场 (CTF教学, 仅供学习)

🔗 点击访问项目地址 GitHub - lilili9646464/biohazard-ctf: 🧪 BioHazard CTF Lab - 生化公司内网渗透实训靶场 (CTF教学, 仅供学习)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #POC

📦 项目名称: Mammotion-l4wnm0w3r
👤 项目作者: ClankerPwn
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 07:01:07

📝 项目描述:
Mammotion l4wnm0w3r — cuz sometimes ya gotta mow someone else's lawn just for fun

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exchange #POC

📦 项目名称: aidlc-employee-skill-exchange-poc
👤 项目作者: jjoyjoshua
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 07:00:21

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #RCE

📦 项目名称: log4j2-fois-rce
👤 项目作者: yijinglab
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 06:57:34

📝 项目描述:
log4j-4255

🔗 点击访问项目地址 GitHub - yijinglab/log4j2-fois-rce: log4j-4255
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: Project-CVE-2026-33017
👤 项目作者: e4zyy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 06:55:31

📝 项目描述:
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

🔗 点击访问项目地址 GitHub - e4zyy/Project-CVE-2026-33017: CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: homebrew-tap
👤 项目作者: satishbabariya
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 06:06:46

📝 项目描述:
Homebrew tap for sandbox — run coding agents in Apple Virtualization VMs whose network egress they cannot bypass.

🔗 点击访问项目地址 satishbabariya/homebrew-tap
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: codemender-security
👤 项目作者: edwardc-gcp
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 05:58:05

📝 项目描述:
Autonomous security auditing, exploit PoC validation, and patch remediation skill for Google Antigravity

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: web-app-pentesting
👤 项目作者: vimalraj-sec
🛠 开发语言: Unknown
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 05:52:38

📝 项目描述:
Complete web application penetration testing reference — OWASP Top 10:2025 aligned, covering injection, access control, API security, file upload attacks, and client-side exploits.

🔗 点击访问项目地址 GitHub - vimalraj-sec/web-app-pentesting: Complete web application penetration testing reference — OWASP Top 10:2025 aligned, covering…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules #malware

📦 项目名称: YaraXGUI
👤 项目作者: Owl4444
🛠 开发语言: Python
Star数量: 28 | 🍴 Fork数量: 6
📅 更新时间: 2026-08-28 04:19:16

📝 项目描述:
Pyside6 implementation of YaraXGUI

🔗 点击访问项目地址 GitHub - Owl4444/YaraXGUI: Pyside6 implementation of YaraXGUI
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: CWE-Cover-2.0
👤 项目作者: ticarollamas-arch
🛠 开发语言: TypeScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 01:55:58

📝 项目描述:
CWE-Cover 2.0 — Plataforma de análise de segurança que combina descoberta de superfície, detecção baseada em CWE e integração com scanners como Nuclei para organizar, validar e gerar relatórios técnicos de vulnerabilidades em ambientes autorizados.

🔗 点击访问项目地址 GitHub - ticarollamas-arch/CWE-Cover-2.0: CWE-Cover 2.0 — Plataforma de análise de segurança que combina descoberta de superfície…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates

📦 项目名称: Nuclei_templates
👤 项目作者: Sivarooprr
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 04:33:49

📝 项目描述:
Nuclei template

🔗 点击访问项目地址 GitHub - Sivarooprr/Nuclei_templates: Nuclei template
Back to Top