
ThreatPort | External Attack Surface Management & CTI
监控外部攻击面,自动检测安全漏洞和暴露点。
@tugayakin34 · X
ThreatPort is an all-in-one Cyber Threat Intelligence & Attack Surface Management platform
完整作品展
技术栈
14 projects

监控外部攻击面,自动检测安全漏洞和暴露点。
@tugayakin34 · X
ThreatPort is an all-in-one Cyber Threat Intelligence & Attack Surface Management platform

为网络设备自动备份配置并用E2EE端到端加密保护。
Willdom1986 · V2EX
多年前考过 CCNP 网络工程师,以前有一个很头疼的地方就是网络设备配置丢失引发的各种故障。后来越发觉得,网络设备的配置实际上是一个非常关键的数字资产。 为此,我利用周末时间开发了 XConf ( https://xconf.ai) 来解决这个问题。 产品主要就是想解决两个问题:**自动化的灾备高可用**,以及**端到端的安全**。 * **自动备份与灾备**:支持将配置定时备份到云端。如果网络断连了,探针会自动在本地离线队列里暂存配置,等连接恢复后自动重传。 * **端到端加密**:本地的 Go 探针是完全开源的,会自动在内存中对密码进行流式脱敏,并在上传前通过 AES-256-GCM 在本地加密。SaaS 后台拿到的只有密文,解密和版本比对( Diff )都完全在你的浏览器本地沙盒里通过 WebCrypto API 进行。 * **打磨版的配置对比 Diff**:我花了一些功夫打磨了浏览器端的配置版本对比功能,力求让日常比对的交互体验足够丝滑。 * **AI 安全基线审查**:系统集成了 AI 辅助的安全基线审查,可以一键检查和分析配置中的潜在风险。 因为目前完全是我利用业余时间(主要在周末)维护,所以确实没精力提供工作日的在线即时客服。大家使用过程中遇到任何 Bug ,欢迎随时去 GitHub 提 Issue ,我会在周末集中修复和跟进。 目前公测已开放,不需要邀请码即可注册,欢迎大家体验吐槽。 探针 agent 开源地址: https://github.com/willdom-lee/xconf-agent 官方网站: https://xconf.ai

USend 是无需登录的安全文件转移工具,用一次性配对码在设备间传输文件或文本,支持端到端加密和自动删除。
@FrankFika · X
Still using a chat app to send files to yourself? I built USend: no sign-in, no app, no permanent share link. An 8-digit code moves a file or text between devices. Browser-side encryption. Auto-delete after receipt or expiry. Try it: #VibeCoding #OpenSource

使用AI增强的安全分析扫描代码和应用漏洞。
u/swifi_ai · Reddit
After 10 years of keeping this idea alive, I finally launched my AI security platform to beta After more than 10 years of keeping this idea alive in one form or another, I finally pushed Swifi live to beta: https://swifi.ai Swifi is an AI-augmented application security platform. The goal: combine traditional security scanning with AI so teams can understand risk across code, vulnerabilities, and production context without stitching together a dozen disconnected tools. Why now? AI change

Sentrint 扫描 AI 应用以查找数据库暴露、密钥泄露和认证缺陷等安全问题。
@Sentrint · X
Made Sentrint after seeing how many vibe-coded apps ship with RLS switched off. Point it at a GitHub repo and it finds open user tables, exposed keys and auth checks that only run in the browser. Free scan is the whole scan, no card.

通过 GridSync API 实时同步跨设备数据,具有自动威胁检测和清理功能。
@mygridsyncdev · X
Just launched GridSync ⚡️ Sub-150ms zero-trust payload inspection & real-time sync for modern APIs. Try the free tier on RapidAPI or check out the docs: #buildinpublic #API #FastAPI

Veridome Surface:扫描AI应用部署的安全问题并生成修复。
maor_dayan_ · Product Hunt
Veridome Surface The security layer for apps you built with AI

探索2020年以来的CVE趋势和漏洞严重性,按报告组织分类。
u/Secret_Appeal6271 · Reddit
Agents are more capable, and susceptible to exploits, than ever. We're working to stop this from hurting users. AI agents are starting to get real access like GitHub tokens, cloud credentials, customer data, deploy permissions. Not coincidentally, the rate of major cybersecurity incidents is rising rapidly. See for yourself: https://epoch.ai/data/cve?view=graph https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/ My friend and I, both AI researchers, are working o

10级提示词注入谜题,尝试操纵AI代理的行为。
Getchowned · HN
The AI Lethal Trifecta

Create isolated, stateful development environments for coding agents and engineering teams.
@simskiiee · X

即时部署您的vibe-coded应用,自带数据库、文件存储和实时交互。
@Fusekit_cloud · X
Especially when that vibe coded app is internal and hyperspecific to your needs! Try to deploy your vibe coded apps and automatically get a full database, file storage, realtime interactions and many morr thing! Free to start without a credit card right now :)
