Official intelligence summary

HAIJA INTEL REPORT

Generated 26/05/2026, 09:14. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources3
Tweets / X12
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

12 items
@Jhaddix avatar
Jhaddix @Jhaddix
25 May, 12:41 · core
0.32
Stop blaming AI slop for what bug bounty platforms did to themselves. wrote down some thoughts about the state of triage
tweet media
@intigriti avatar
intigriti @intigriti
25 May, 11:05 · secondary
0.22
post your favorite bug bounty meme to cheer your fellow hunters up this Monday!
@_xpn_ avatar
_xpn_ @_xpn_
25 May, 20:37 · core
0.20
Been messing about with GEPA optimisation in Python after coming across it on @dreadnode platform... it's simple but amazingly effective. I'll write it up when I get a sec :D
tweet media
@SpecterOps avatar
SpecterOps @SpecterOps
25 May, 16:56 · core
0.20
This #MemorialDay, we remember those who served and sacrificed for our nation. From all of us at SpecterOps, we are grateful to those heroes and the families who carry their legacy forward.
tweet media
@mrgretzky avatar
mrgretzky @mrgretzky
25 May, 15:00 · core
0.20
begin-re is back Lost the domain, kept the course, improved the looks. You can find it now at
tweet media
@_xpn_ avatar
_xpn_ @_xpn_
25 May, 14:47 · core
0.20
Every time I hear of someone complaining about a nerfed SOTA model, I always think back to this Counter Strike story xD
tweet media
@mrgretzky avatar
mrgretzky @mrgretzky
25 May, 14:45 · core
0.20
We live in interesting times. Last month Linux patched a core uaf in the epoll subsystem, we rarely see these kind of bugs. As i like these kind of bugs, i wrote a few words about it here:
@_xpn_ avatar
_xpn_ @_xpn_
25 May, 14:22 · core
0.20
Nothing in life can't be solved by getting a tattoo. Bigger the problem, bigger the tattoo.
@gynvael avatar
gynvael @gynvael
25 May, 18:43 · secondary
0.14
State near lunch. It was just an empty table after few more minutes. Thank you to everyone for your love and interest in our zine! Grab a Paged Out! if you're at @CONFidenceConf! We have 500 of them to give away
tweet mediatweet media
@Mandiant avatar
Mandiant @Mandiant
25 May, 18:00 · secondary
0.14
Abusing LOLBins is a primary vector for stealthy attacks. Hunt them down using automated behavior telemetry in Google TI! #GoogleTIMondays
tweet media
@brutelogic avatar
brutelogic @brutelogic
25 May, 16:35 · secondary
0.14
Parsing Confusion - Cloud Pipelines An AWS API Gateway (policy) and a downstream Node.js Lambda (execution) use different engines. One layer takes the first value, the other layer takes the second. Always use TRUE and FALSE at the same time.
tweet media
@vxunderground avatar
vxunderground @vxunderground
25 May, 16:23 · secondary
0.14
The Pope is meeting up with Claude nerds to bless vibe coded slop, or something, I don't know.
tweet media

Regular sources

3 items
1.00general · 25 May, 14:45bleepingcomputer.comAttack path

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to …

1.00exploit · 25 May, 08:582 mentionsseclists.org

Re: Coordinated Disclosure in the LLM Age

Posted by ROI AI on May 24 Yes, apologies for that. And apologies to anyone who felt I was being repetitive. However, fwiw, my only agenda here is seeing open source be … | Posted by Jacob Bachmeyer on May 24 I want to make clear that the message quoted above bungled quoting in a way that left my signature line after what I now presume to b…