Official intelligence summary

HAIJA INTEL REPORT

Generated 01/06/2026, 09:15. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources5
Tweets / X10
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

10 items
@SpecterOps avatar
SpecterOps @SpecterOps
30 May, 00:37 · core
0.54
To defend Azure & Entra ID, you first need to understand how attackers see them. Join our Azure training at #BHUSA & learn the misconfigurations adversaries look for through hands-on labs built around real-world attack paths. https:// ghst.ly/4uii3Ua
tweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
31 May, 09:18 · core
0.46
Oh yes “Mom, how did we got so rich?” “You father stopped d*cking around with bug bounty programs and sold his exploits to Western governments”
tweet media
@intigriti avatar
intigriti @intigriti
29 May, 11:05 · secondary
0.36
Escalating SQLi to RCE! Found a SQL injection? Here's how you can quickly escalate it to remote code execution across different database engines! Open this thread! Here's how you can quickly escalate your SQL injections to RCE on different databases! A small thread!
@intigriti avatar
intigriti @intigriti
30 May, 18:09 · secondary
0.35
Latest Bug Bytes is live! This month's issue is as usual packed with bug bounty tips: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API
tweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
29 May, 23:32 · secondary
0.35
We detected indirect prompt injection on a fake Excel template store. Hidden via white text, the prompt uses social engineering to manipulate AI agents into boosting SEO, aiming to funnel users to a malicious Chrome extension. Details at https:// bit.ly/3RCl2s2
tweet mediatweet media
@Synack avatar
Synack @Synack
29 May, 16:04 · secondary
0.29
Meet with Synack during Infosecurity Europe 2026 just outside the show for relaxed, one-to-one conversations. Drinks are on us. Learn how Sara AI pentesting combines AI-driven testing with human expertise to validate real exploitable risk faster. Register here:
tweet media
@intigriti avatar
intigriti @intigriti
29 May, 11:05 · secondary
0.29
6 resources to delve more into SQLi exploitation! A thread!
tweet media
@brutelogic avatar
brutelogic @brutelogic
30 May, 13:46 · secondary
0.28
Last call, ending this weekend. KNOXSS - Comprehensive XSS Tool http:// knoxss.pro Ebooks - First Bounty, SSRF, Bypass http:// brutelogic.net/ebooks Brute One - Tool Enabled AI Assistant http:// brutelogic.net/brute-one #BugBounty #PenTesting
tweet media
@_RastaMouse avatar
_RastaMouse @_RastaMouse
30 May, 20:48 · core
0.26
It’s a long one , but I had a great time yapping with Kirk about how I stumbled into offensive security, and the latest Twitter drama Full new episode of whoami w/ @0xTriboulet. We talk about his journey into offensive security, AI, recent disclosures, and research/life balance.
tweet media
@SentinelOne avatar
SentinelOne @SentinelOne
29 May, 22:10 · secondary
0.25
Law enforcement took down a Russian-linked hosting network, a ransomware group escalated to dispatching physical operatives for data extortion, and a massive supply chain campaign targets developer environments and AI tools. This is the Good, Bad & Ugly. GOOD - Dutch
tweet media

Regular sources

5 items
1.00general · 31 May, 10:00helpnetsecurity.com

Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto paym…

1.00general · 30 May, 08:41thehackernews.comWild exploit

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. …

1.00general · 29 May, 14:59securityweek.comRCE

Gogs Zero-Day Exposes Servers to Remote Code Execution

The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with maliciou…

0.91general · 29 May, 20:07thehackernews.comAttack path

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markd…

0.89exploit · 29 May, 08:59seclists.org

Re: Linux: DMA-after-unmap race in ZCRX via netif_rxq_cleanup_unlease() ordering inversion (netkit + page_pool)

Posted by Solar Designer on May 28 Hi Ahmed, https://oss-security.openwall.org/wiki/mailing-lists/oss-security#list-content-guidelines "Please don't cross-post messages …