📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: smart-contract-security-training
👤 项目作者: Doritra
🛠 开发语言: Solidity
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 16:00:48

📝 项目描述:
Hands-on smart contract security training: Ethernaut (31/31) + Ethernaut 2025 (7/9) + Damn Vulnerable DeFi exploits, all runnable Foundry PoCs with HackenProof-style reports

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: opencode-security-autofix
👤 项目作者: xiaobaozi01
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 16:32:36

📝 项目描述:
面向 OpenCode 的安全漏洞自动修复工具包,包含报告解析、修复路由、构建测试、重扫与结果报告。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: CodeAnalyzer
👤 项目作者: IvanGranero
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 13:29:23

📝 项目描述:
Multi-Agent Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #EXP

📦 项目名称: nacos-v3-attack
👤 项目作者: TlyHj
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 12:59:37

📝 项目描述:
Nacos 3.0.0~3.2.3 鉴权作用域错配漏洞 PoC & EXP | 未授权创建管理员等价账户完全接管

🔗 点击访问项目地址 GitHub - TlyHj/nacos-v3-attack: Nacos 3.0.0~3.2.3 鉴权作用域错配漏洞 PoC & EXP | 未授权创建管理员等价账户完全接管
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #EXP #POC

📦 项目名称: ZoneMinder-v1.29.0
👤 项目作者: s1lentf00thold
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 12:52:57

📝 项目描述:
ZoneMinder 1.29.0 rce

🔗 点击访问项目地址 GitHub - s1lentf00thold/ZoneMinder-v1.29.0: ZoneMinder 1.29.0 rce
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Web-Application-Pentest-Rejetto-File-Server-RCE
👤 项目作者: EsraaAlsaedi
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 13:04:26

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - EsraaAlsaedi/Web-Application-Pentest-Rejetto-File-Server-RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
👤 项目作者: hackpatato
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 13:57:18

📝 项目描述:
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules

🔗 点击访问项目地址 GitHub - hackpatato/CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules: CVE-2026-33057 - Mesop Unauthenticated RCE PoC…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-33017-PoC-Reverse-Shell
👤 项目作者: ahseven
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 13:58:13

📝 项目描述:
CVE-2026-33017 PoC Reverse Shell

🔗 点击访问项目地址 GitHub - ahseven/CVE-2026-33017-PoC-Reverse-Shell: CVE-2026-33017 PoC Reverse Shell
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: StagedWebLoader
👤 项目作者: 0xStalic
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 12:19:53

📝 项目描述:
A shellcode loader which visits a webpage, downloads the contents, and then attempts to allocate a remote thread to spawn the malicious process.

🔗 点击访问项目地址 GitHub - 0xStalic/StagedWebLoader: A shellcode loader which visits a webpage, downloads the contents, and then attempts to allocate…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-10036-speechbrain-rce
👤 项目作者: SaiTeja-Erukude
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 12:37:50

📝 项目描述:
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

🔗 点击访问项目地址 GitHub - SaiTeja-Erukude/CVE-2026-10036-speechbrain-rce: SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: Project-CVE-2026-50751
👤 项目作者: e4zyy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 11:07:37

📝 项目描述:
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

🔗 点击访问项目地址 GitHub - e4zyy/Project-CVE-2026-50751: IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: OpenSourceSoftware-SCA
👤 项目作者: honkerlmf
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 11:00:56

📝 项目描述:
软件供应链开源组件成分漏洞安全扫描工具(Open Source Software SCA)

🔗 点击访问项目地址 GitHub - honkerlmf/OpenSourceSoftware-SCA: 软件供应链开源组件成分漏洞安全扫描工具(Open Source Software SCA)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: radix-vulnerability-scanner
👤 项目作者: equinor
🛠 开发语言: Go
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 09:58:04

📝 项目描述:
Scan components and jobs in RadixDeployments for vulnerabilities

🔗 点击访问项目地址 GitHub - equinor/radix-vulnerability-scanner: Scan components and jobs in RadixDeployments for vulnerabilities
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: luck7even-AI-Triage-Shield
👤 项目作者: seunghyun-sh
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 09:32:09

📝 项目描述:
AI-assisted XSS and SQL injection assessment dashboard for an authorized training environment

🔗 点击访问项目地址 GitHub - seunghyun-sh/luck7even-AI-Triage-Shield: AI-assisted XSS and SQL injection assessment dashboard for an authorized training…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: Zimbra-CVE-2026-73570-Rules
👤 项目作者: INFOKOM-KI
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 10:43:28

📝 项目描述:
Wazuh Rules for Detection Zimbra (CVE-2026-73570).

🔗 点击访问项目地址 GitHub - INFOKOM-KI/Zimbra-CVE-2026-73570-Rules: Wazuh Rules for Detection Zimbra (CVE-2026-73570).
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CTT-Enhanced-CVE-2026-46339-Exploit-Engine
👤 项目作者: SimoesCTT
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 10:58:40

📝 项目描述:
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.

🔗 点击访问项目地址 GitHub - SimoesCTT/CTT-Enhanced-CVE-2026-46339-Exploit-Engine: A specialized Python framework that executes unauthenticated remote…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: SecretScrub-Logger
👤 项目作者: DonnieMarco
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 10:03:37

📝 项目描述:
A Burp Suite extension that logs in-scope HTTP traffic as rotating JSONL files while redacting tokens, session cookies, and CSRF secrets.

🔗 点击访问项目地址 GitHub - DonnieMarco/SecretScrub-Logger: A Burp Suite extension that logs in-scope HTTP traffic as rotating JSONL files while redacting…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: Nacos-QVD-2026-59388
👤 项目作者: Xxh-v
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 09:44:23

📝 项目描述:
Nacos 未授权管理员账号创建漏洞复现

🔗 点击访问项目地址 GitHub - Xxh-v/Nacos-QVD-2026-59388: Nacos 未授权管理员账号创建漏洞复现
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: phantom-xss
👤 项目作者: kishwordulal2005
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 10:01:14

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - kishwordulal2005/phantom-xss
Back to Top