Official intelligence summary

HAIJA INTEL REPORT

Generated 02/06/2026, 09:16. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources4
Tweets / X11
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

11 items
@mrgretzky avatar
mrgretzky @mrgretzky
01 Jun, 16:47 · core
0.56
I wanted to address the speculation about the recently introduced Device Bound Session Credentials (DBSC) security feature in Google Chrome. Does it help increase the security of session cookies against infostealer malware and MFA phishing? The feature has been available and Goog
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
01 Jun, 15:04 · core
0.54
I've published an article on how an attacker could break into the Claude Code supply chain! We've published a new blog post by RyotaK @ryotkak. He discovered a vulnerability that allows attackers to bypass the permission controls of Claude Code GitHub Actions via a GitHub issue,
tweet media
SP
SpecterOps @SpecterOps
01 Jun, 19:50 · core
0.50
During an assessment, our team discovered that StrongDM auth state files containing JWTs & key material could be reused across hosts to obtain authenticated sessions & access infrastructure resources (CVE-2026-4387). Re…
_X
_xpn_ @_xpn_
01 Jun, 19:06 · core
0.48
I'm excited to be able to finally publish the public disclosure for CVE-2026-4387. Check out my blog on discovering the reuse of the state.kv file to get authenticated sessions with StrongDM (now fixed).
@SpecterOps avatar
SpecterOps @SpecterOps
01 Jun, 22:45 · core
0.40
Attending #CiscoLive in Las Vegas? Stop by booth 2206 and connect with our team. We'd love to discuss your identity attack path management questions and show you how BloodHound Enterprise helps organizations uncover and reduce hidden risk.
tweet media
@RedCanary avatar
RedCanary @RedCanary
01 Jun, 23:25 · secondary
0.34
Tomorrow we're live at 1 p.m. ET / 10 a.m. PT for our latest episode of SecOps Weekly! Phil Hagen and Chris Brook are hopping on to chat about the latest security trends and answer audience questions from our mailbag. Join us live to hear their take and learn what you and your
tweet media
@SpecterOps avatar
SpecterOps @SpecterOps
01 Jun, 22:52 · core
0.34
Don't miss "Signal to Enforcement: A Coordinated Security Walkthrough" featuring @jaredcatkinson at 4:30 PM. Follow a real-world attacker path across identity, SaaS, devices, and networks, and see how integrated security architectures enable coordinated response and enforcement.
@nahamsec avatar
nahamsec @nahamsec
01 Jun, 14:45 · core
0.34
I found a $3,000 bug in an AI chatbot using prompt injection. Video https:// youtu.be/Q6hQlM6f6Cs Lab https:// app.hackinghub.io/hubs/shopmate
tweet media
@RedCanary avatar
RedCanary @RedCanary
01 Jun, 20:38 · secondary
0.32
Your “agentic coworker” is sending suspicious messages via Microsoft Teams. It’s going to need to have a chat with the agentic HR department. Read Part 2 of our series on investigating suspicious AI workflows in Entra ID: https:// redcanary.com/blog/threat-de tection/entra-id-ai-
tweet media
@Sysdig avatar
Sysdig @Sysdig
01 Jun, 16:00 · secondary
0.32
The problem with agentic security workflows isn't access to data. It's making that data callable from the agent. The Sysdig MCP server on AWS Marketplace closes that gap, inside Amazon Bedrock AgentCore. Read the blog: https:// okt.to/uVP2Fe #CloudSecurity
tweet media
@vxunderground avatar
vxunderground @vxunderground
01 Jun, 22:28 · secondary
0.29
As I'm sure you've all seen by now, nerds have been exploiting Meta's AI agent goop to steal Instagram accounts. The Instagram AI agent for support could be convinced to reset the credentials to other users accounts by asking nicely and do a super gnarly kickflip on a
tweet media

Regular sources

4 items
1.00general · 01 Jun, 16:17helpnetsecurity.comRCEWild exploit

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089)

CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB)…

1.00general · 01 Jun, 15:59thehackernews.comWild exploitAttack path

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and t…

1.00general · 01 Jun, 06:00helpnetsecurity.com

145 AI laws passed in 2025 and privacy teams aren’t catching a break

145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI …

0.89exploit · 01 Jun, 08:24seclists.orgResearch

CyberDanube Security Research 20260528-0 | Multiple Vulnerabilities in Multiple Vulnerabilities in Mennekes Amtron Series

Posted by Thomas Weber | CyberDanube via Fulldisclosure on May 31 CyberDanube Security Research 20260528-0 https://www.mennekes.at/ found|...