​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-46331-audit
👤 项目作者: Quaerendir
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 10:20:58

📝 项目描述:
cve-2026-46331-audit script

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #子域名 #指纹

📦 项目名称: srcradar-mcp-server
👤 项目作者: usdagfhjkda
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 10:04:58

📝 项目描述:
面向 agent 的持久化业务级攻击面知识库。把 srcradar 的"业务名 → 法律实体图谱 → 主动测绘资产(小程序/公众号 + Web 范围 → 子域名/端口/指纹) → 每日增量 diff" 通过 MCP 协议暴露出来,让任何 agent 在攻击前直接拿到已知资产清单与最新变动 —— 跳过信息收集,从已识别的目标开始

🔗 点击访问项目地址 GitHub - usdagfhjkda/srcradar-mcp-server: 面向 agent 的持久化业务级攻击面知识库。把 srcradar 的
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: web-app-security-lab
👤 项目作者: godfredachie-web
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 09:05:13

📝 项目描述:
A hands-on web application penetration testing and threat remediation repository documenting the identification, exploitation, and secure code mitigation of OWASP Top 10 vulnerabilities (including SQL Injection, DOM-based XSS, and Broken Access Control) using OWASP Juice Shop in a Dockerized Ubuntu Linux environment.

🔗 点击访问项目地址 GitHub - godfredachie-web/web-app-security-lab: A hands-on web application penetration testing and threat remediation repository…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-18143
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 08:00:40

📝 项目描述:
Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_file() with attacker-controlled .php filenames into web-accessible RFQ temp storage (popup quote flow required). CVSS 9.8. Python check/exploit PoC → pocbit.org/pocs/cve-2026-18143

🔗 点击访问项目地址 GitHub - murrez/CVE-2026-18143: Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-65320-fastcore
👤 项目作者: rahulreddykarne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 08:40:55

📝 项目描述:
Path Traversal (Tar Slip) in fastcore via untar_dir()

🔗 点击访问项目地址 GitHub - rahulreddykarne/CVE-2026-65320-fastcore: Path Traversal (Tar Slip) in fastcore via untar_dir()
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp2model-skill
👤 项目作者: falc0n-researcher
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 06:37:23

📝 项目描述:
The machine builds comprehension. The human keeps judgment. AI is an intelligence engine, not an exploit button.

🔗 点击访问项目地址 GitHub - falc0n-researcher/burp2model-skill: The machine builds comprehension. The human keeps judgment. AI is an intelligence…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: network-vulnerability-scanner
👤 项目作者: redkarromit23-sketch
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 07:27:58

📝 项目描述:
Python-based network vulnerability scanner with port scanning, banner analysis, and NVD CVE lookup.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner_top10
👤 项目作者: arjunbp
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 07:50:33

📝 项目描述:
Python-based web vulnerability scanner for authorized security testing.

🔗 点击访问项目地址 GitHub - arjunbp/web-vulnerability-scanner_top10: Python-based web vulnerability scanner for authorized security testing.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: vitrine
👤 项目作者: rakshit-737
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 07:34:58

📝 项目描述:
Static-first PE triage with explainable verdicts and auto-generated YARA rules

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-14281
👤 项目作者: langz337
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 07:15:04

📝 项目描述:
CVE-2026-14281

🔗 点击访问项目地址 GitHub - langz337/CVE-2026-14281: CVE-2026-14281
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Network_Vulnerability_Scanner
👤 项目作者: zeshanmain555-byte
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 06:48:44

📝 项目描述:
A web-based network vulnerability scanner built with Flask, Nmap, WhatWeb, Nikto, and NVD CVE correlation.

🔗 点击访问项目地址 GitHub - zeshanmain555-byte/Network_Vulnerability_Scanner: A web-based network vulnerability scanner built with Flask, Nmap, WhatWeb…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: Webscan
👤 项目作者: npcadmic-misc
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 06:20:17

📝 项目描述:
一个简易的web漏洞扫描系统

🔗 点击访问项目地址 npcadmic-misc/Webscan
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: Root-My-Device
👤 项目作者: WitAqua-tools
🛠 开发语言: Kotlin
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 06:48:04

📝 项目描述:
KSU installer for supported firmware with CVE-2026-43499

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: wordpress-upgrade-check
👤 项目作者: itskill-jp
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 06:55:36

📝 项目描述:
Read-only check of every WordPress core version on a server. Flags CVE-2026-87902 (fixed in 7.1.2 and backports), auto-updates turned off, and published attack indicators.

🔗 点击访问项目地址 GitHub - itskill-jp/wordpress-upgrade-check: Read-only check of every WordPress core version on a server. Flags CVE-2026-87902…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-43682
👤 项目作者: petermalone
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 05:51:00

📝 项目描述:
CVE-2026-43682: HFS+ B-tree kernel heap overflow in macOS

🔗 点击访问项目地址 GitHub - petermalone/CVE-2026-43682: CVE-2026-43682: HFS+ B-tree kernel heap overflow in macOS
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Beacon

📦 项目名称: Kut-Security-Suit
👤 项目作者: cihanuralkaya
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 05:00:51

📝 项目描述:
Corporate XDR/EDR/MDM + SOC endpoint security platform in Go; agent-to-C2 over gRPC + mTLS (TLS 1.3). Kurumsal uc nokta guvenlik platformu.

🔗 点击访问项目地址 GitHub - cihanuralkaya/Kut-Security-Suit: Corporate XDR/EDR/MDM + SOC endpoint security platform in Go; agent-to-C2 over gRPC +…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: hfaBUGTo
👤 项目作者: boom5497
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 03:29:20

📝 项目描述:
2022计算机毕设一套 终稿 (论文+前后端程序源代码)基于shiro框架的渗透测试研究_e55821e8-81e7-4719-aaf7-abbfc684ba7d.zip

🔗 点击访问项目地址 GitHub - boom5497/hfaBUGTo: 2022计算机毕设一套 终稿 (论文+前后端程序源代码)基于shiro框架的渗透测试研究_e55821e8-81e7-4719-aaf7-abbfc684ba7d.zip
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: ysQpzWdD
👤 项目作者: boom5497
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 03:43:28

📝 项目描述:
2022计算机毕设一套 终稿 (论文+前后端程序源代码)基于Jboss框架的渗透测试研究_7343e07d-dc1f-43ad-807b-cb4efaff1aa5.zip

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin

📦 项目名称: exp-projectdiscovery-nuclei-burp-plugin
👤 项目作者: osflaky
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 03:59:55

📝 项目描述:
snapshot of projectdiscovery/nuclei-burp-plugin at a pinned commit, for cross platform ci legs

🔗 点击访问项目地址 GitHub - osflaky/exp-projectdiscovery-nuclei-burp-plugin: snapshot of projectdiscovery/nuclei-burp-plugin at a pinned commit, for…
Back to Top