Official intelligence summary

HAIJA INTEL REPORT

Generated 29/05/2026, 09:17. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources8
Tweets / X7
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

7 items
AL
albinowax @albinowax
28 May, 16:48 · core
1.00
On an asset under our continuous monitoring, our pentester @nol_tech turned a SELECT-only PostgreSQL SQLi in Drupal (CVE-2026-9082) into a full RCE when DB role is superuser. Details below https:// blog.lexfo.fr/drupal-…
@SpecterOps avatar
SpecterOps @SpecterOps
28 May, 21:50 · core
0.68
Phishing sandboxes don’t play fair. In his latest blog, @synzack21 walks through a real red team engagement against modern email sandboxes and techniques that helped keep payload redirects hidden from crawlers while preserving a familiar user experience.
tweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
28 May, 19:26 · secondary
0.49
#TuxBot v3 Evolution: IoT malware/C2 framework tied to AISURU/Keksec. Self-ID "Akiru." 30-plus exploit targets, 1,496 credential pairs, encrypted C2, and DGA. Developers used an LLM to port exploits and write code, leaving traces in some files. Details at https:// bit.ly/3RAFJ7N
tweet mediatweet media
@Rapid7 avatar
Rapid7 @Rapid7
28 May, 15:15 · secondary
0.39
Found an unpatched RCE in Gogs Any authenticated user can get code execution on the server through argument injection into git rebase. Full @rapid7 writeup + @metasploit module available now! https:// rapid7.com/blog/post/ve-a uthenticated-rce-via-argument-injection-gogs-unfixed/
tweet media
@Synack avatar
Synack @Synack
28 May, 20:48 · secondary
0.34
Heading to TechNet Cyber 2026 in Baltimore? Join Synack at Booth 2644 to discuss how AI-powered pentesting and human validation can help your team continuously identify and reduce exploitable risk. Book a 1:1 meeting here: https:// hubs.ly/Q04jfSD_0 #technetcyber2026
tweet media
@SpecterOps avatar
SpecterOps @SpecterOps
28 May, 20:35 · core
0.34
Red team engagement ≠ red team exercise. One measures your detection and response. The other develops it. Most orgs invest in the first. Far fewer invest in the second. @Ne0nd0g explains why structured practice belongs in every mature security program.
tweet media
@_xpn_ avatar
_xpn_ @_xpn_
28 May, 12:10 · core
0.34
Getting Oracle vibes xD https:// x.com/mikko/status/6 31110787252232192?s=20 … What next? MSRC Swatting researchers? "Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity - coordinating as needed with law enforcem

Regular sources

8 items
1.00general · 28 May, 16:25bleepingcomputer.comRCE

New Gogs zero-day flaw lets hackers get remote code execution

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. [...]

1.00general · 28 May, 14:55securityweek.comWild exploit

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Criti…

1.00critical · 28 May, 14:00cisa.gov

Supply Chain Compromises Impact Nx Console and GitHub Repositories

CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Develop…

1.00exploit · 28 May, 06:112 mentionsseclists.org

Re: Linux: DMA-after-unmap race in ZCRX via netif_rxq_cleanup_unlease() ordering inversion (netkit + page_pool)

Posted by Jacob Bachmeyer on May 27 This report reads like the product of an "AI" system. What "AI" assisted you in preparing this report? [I am sending this to the list… | Posted by Prénom? Ahmed on May 27 Hello, I would like to report a source-proven teardown ordering bug in the Linux kernel that can lead to a DMA-after-unmap race conditi…

1.00general · 28 May, 00:00unit42.paloaltonetworks.com

Out of the Crypt: The Evolving Cyber Extortion Economy

Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cy…

0.89exploit · 28 May, 09:09seclists.org

CIFSwitch: Linux kernel/cifs-utils local root via forged cifs.spnego upcall

Posted by manizada on May 28 Hi folks, Emailing here now that the embargo agreed upon with linux-distros@ has expired. Flagging a local root vulnerability spanning both …