📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: secure-currency-converter
👤 项目作者: Mdsoare
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 18:17:22

📝 项目描述:
Conversor de câmbio desenvolvido para fins de estudo em AppSec e Arquitetura Front-end. Implementa mitigação de XSS, CSP restrita, Rate Limiting no cliente (Debounce) e segregação estrita de assets (HTML, CSS, JS).

🔗 点击访问项目地址 GitHub - Mdsoare/secure-currency-converter: Conversor de câmbio desenvolvido para fins de estudo em AppSec e Arquitetura Front…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: POC-GeoLeak-CVE-2026-52715
👤 项目作者: 686f6c61
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 18:37:45

📝 项目描述:
PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit time-based/boolean-based + exfiltracion sin comas en payload.

🔗 点击访问项目地址 GitHub - 686f6c61/POC-GeoLeak-CVE-2026-52715: PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: MalwareAnalysis-in-PDF
👤 项目作者: filipi86
🛠 开发语言: Unknown
Star数量: 236 | 🍴 Fork数量: 29
📅 更新时间: 2026-08-14 17:56:57

📝 项目描述:
Malicious PDF files recently considered one of the most dangerous threats to the system security. The flexible code-bearing vector of the PDF format enables to attacker to carry out malicious code on the computer system for user exploitation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: BurpSuiteCommunity-Search-Plugin
👤 项目作者: mohammedshine-beta
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 17:29:45

📝 项目描述:
Burp Suite Community Edition extension providing a powerful HTTP traffic search feature. Search captured requests and responses using keywords or regex, with filters, match highlighting, snippets, and searchable traffic history. Built for penetration testers to quickly find secrets, tokens, endpoints, parameters, and other interesting patterns.

🔗 点击访问项目地址 mohammedshine-beta/BurpSuiteCommunity-Search-Plugin
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: SquidSec_BurpAIBridge
👤 项目作者: SquidSec
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 17:42:45

📝 项目描述:
Burp Suite extension: loopback MCP/HTTP API so agents can drive live Burp (scope, history, send, scanner, collaborator).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: ResetNightmare
👤 项目作者: Semperis-Community
🛠 开发语言: PowerShell
Star数量: 194 | 🍴 Fork数量: 34
📅 更新时间: 2026-08-14 17:21:20

📝 项目描述:
POC tool for ResetNightmare (CVE-2026-27912)

🔗 点击访问项目地址 GitHub - Semperis-Community/ResetNightmare: POC tool for ResetNightmare (CVE-2026-27912)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-12345-poc
👤 项目作者: zahidec0de
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 17:51:16

📝 项目描述:
Proof of Concept (PoC) for CVE-2026-64638, a reflected XSS in WordPress Core < 7.0.3.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-yara-rules
👤 项目作者: raulsineiro
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 17:05:37

📝 项目描述:
Reglas YARA para detección de malware, desarrolladas a partir de análisis de muestras reales.

🔗 点击访问项目地址
🫤😐🫥😶🤥🫠🤫🫡🫢
😑 N9 国际认证 | 信誉平台
支持5倍验资 【验资:
@N9KF
担保域名:N9.TOP 点击查看
⚡️⚡️⚡️⚡️
💝
新会员好礼
注册就送28.8U
新人首存/二存/三存最高赠送
8️⃣8️⃣8️⃣8️⃣U
💝
老会员好礼
电子狂欢每日存款赠送10%
充值笔笔送3%无上限
夜间充值最高可优惠8888U

⚡️⚡️⚡️⚡️⚡️⚡️
⚡️⚡️⚡️⚡️⚡️⚡️⚡️
香港六合彩
4️⃣8️⃣.8️⃣
加拿大28全网返水最高

⚡️注册网址:N9.PRO

😇🧐🧐😗🧐😙😄
⚡️ 官方客服: @N9KF
⚡️ 官方飞投: @N9N9
⚡️ 彩票客服: @N9CP
⚡️ 彩票飞投: @N9N9N9
⚡️ 福利频道: @N9pd888
⚡️ 注册网址: N9.COM【USDT】
⚡️ 注册网址: N9.COM【人民币】

🔥欢迎各位老板加入N9国际娱乐城!
🔥关注N9官方频道参与更多优惠活动
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: es-chromium
👤 项目作者: EyalSec
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 15:31:03

📝 项目描述:
es-chromium: a Chromium build that tracks attacker-controlled data through V8 and Blink and reports DOM-XSS as a flow, not a guess. The browser agent behind EyalSec.

🔗 点击访问项目地址 GitHub - EyalSec/es-chromium: es-chromium: a Chromium build that tracks attacker-controlled data through V8 and Blink and reports…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: vulnerable-javascript
👤 项目作者: EyalSec
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 15:54:19

📝 项目描述:
Intentionally vulnerable single-page dashboard demonstrating es-chromium DOM-XSS taint tracking - 21 flows across 8 sources and 18 sinks, each reachable from one URL. Demo target only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: JARVIS-vulnerability-scanner
👤 项目作者: Pexel-sibi
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 15:38:54

📝 项目描述:
A lightweight Node.js vulnerability and security configuration scanner.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Network-Vulnerability-Scanner
👤 项目作者: aloksinha-02
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 15:56:04

📝 项目描述:
A Python-based network vulnerability scanner that discovers active devices, scans TCP ports, detects services and banners, performs rule-based risk analysis, and generates security reports.

🔗 点击访问项目地址 aloksinha-02/Network-Vulnerability-Scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-2021-41773-Exploit-Lab
👤 项目作者: SANR01
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 15:59:09

📝 项目描述:
CVE-2021-41773 Exploit Lab

🔗 点击访问项目地址 SANR01/CVE-2021-41773-Exploit-Lab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Remote-Code-Execution-RCE-via-Web-Shell-Upload
👤 项目作者: yagayahani
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 15:42:37

📝 项目描述:
A cybersecurity lab demonstration illustrating how an insecure file upload function in a web application can be exploited using **Burp Suite to achieve Remote Code Execution (RCE) and exfiltrate sensitive server files[span_1](start_span)[span_1](end_span).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: works
👤 项目作者: pionxe
🛠 开发语言: CSS
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 14:37:25

📝 项目描述:
夜航 · works —— 双非计算机学生的网安作品仓公开镜像(Bash → Linux → 网络 → Web → 漏洞复现 → writeup)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据

📦 项目名称: dsh-browser
👤 项目作者: xylt369
🛠 开发语言: TypeScript
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 14:53:07

📝 项目描述:
Browser capability for DeepSeek Harness: headed Edge/Playwright provider, SSRF-safe navigation, a11y-ref clicking, permission gate with auto-remember, gated evaluate

🔗 点击访问项目地址 GitHub - xylt369/dsh-browser: Browser capability for DeepSeek Harness: headed Edge/Playwright provider, SSRF-safe navigation, a11y…
😂😂😂😂 😂😂😂😂 球速 体育 相信品牌的力量,老品牌,值得信赖

🤩🤩🤩🤩🤩🤩🤩 qsty685.cc

🏆 球速体育 豪礼大放送、高端嫩模、劳力士手表、奔驰E300 等大礼等你来豪夺

😀😀😀😀😀😀😀😀😀😀😀😀😀

球速体育 大会员再创新高:
1.
泰国大老板百家乐存50万出512万
2.
斯里兰卡神秘大哥连续5天总提4000万+
3.
实力盘总PA真人喜提990万一路爆红
4.
pp电子糖果1000小注一拉爆出70万大奖

😁😀😁😁😁😁😚🙁😛☺️😉😋以及多种电子钱包存取款、大额出款无忧 (您的最佳选择,欢迎体验)

大额出款额外奖励8888-128888,双重日存彩金128888+4688每日送,周流水彩金68888每周送,双重签到彩金16888+3888送不停

😅😏😃😃🙃😢😅😚😍😀😏😝
#球速体育 安全有保障】
老品牌值得信赖、安全第一、保障第一
不限ip、免实名、免绑卡、免绑手机号码
每日存款彩金每日送,每笔存款加赠1
%

🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩
体育推荐: @qsty789
官方频道:
@PG012456
vip专属热线添加客服领取活动福利
专属客服:
@shiya168
双向用户可联系:
@shiya168_bot


😁😊😁😁 qsty685.cc
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-54433
👤 项目作者: aramosf
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 14:24:11

📝 项目描述:
CVE-2026-54433 Roundcube plain-text email stored XSS PoC

🔗 点击访问项目地址 GitHub - aramosf/CVE-2026-54433: CVE-2026-54433 Roundcube plain-text email stored XSS PoC
Back to Top