HAIJA INTEL REPORT
Tweets / X
9 items







Regular sources
6 itemsbubblewrap CVE-2026-41163: Privilege escalation if setuid root, via ptrace
Posted by Simon McVittie on Apr 25 https://github.com/containers/bubblewrap/security/advisories/GHSA-xq78-7hw4-5jvp Vulnerable: bubblewrap >= 0.11.0 if installed setuid …
rust-openssl-v0.10.78 fixes 5 CVEs
Posted by Alan Coopersmith on Apr 24 https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.78 https://github.com/rust-openssl/rust-openssl/security/adv…
Microsoft to roll out Entra passkeys on Windows in late April
Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late Apri…
Indirect prompt injection is taking hold in the wild
The open web is slowly but surely filling up with “traps” designed for LLM-powered AI agents. The technique, known as indirect prompt injection (IPI), involves hiding (m…
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent …
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving large language models (LLMs), has come under active exploitatio…