Official intelligence summary

HAIJA INTEL REPORT

Generated 08/06/2026, 09:17. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources5
Tweets / X10
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

10 items
@pdiscoveryio avatar
pdiscoveryio @pdiscoveryio
06 Jun, 20:02 · secondary
0.46
Neo uncovered 22 confirmed CVEs across 13 popular open-source projects, including critical issues such as authentication bypasses and remote code execution. It addresses the biggest pain point in AI security: moving beyond noisy false positives to actually prove vulnerabilities
tweet media
@SentinelOne avatar
SentinelOne @SentinelOne
05 Jun, 22:33 · secondary
0.45
Law enforcement dismantled massive cryptocurrency fraud rings, a Chinese cybercrime group expanded its global phishing footprint, and attackers exploited a critical authentication bypass in Palo Alto VPN portals. This is the Good, Bad & Ugly. GOOD - Spanish National
tweet media
@vxunderground avatar
vxunderground @vxunderground
06 Jun, 00:57 · secondary
0.41
> Microsoft GitHub repos banned > "Terms of Service violation" > ??? > Look inside > Was compromised ... was Microsoft going to become a victim of a supply chain attack on their own platform via their own product? More fallout from the Mini Shai-Hulud campaign 49 Microsoft, Azure
tweet mediatweet media
@BishopFox avatar
BishopFox @BishopFox
05 Jun, 20:08 · secondary
0.36
From our recent Red Team special episode of Initial Access:
tweet media
@_dirkjan avatar
_dirkjan @_dirkjan
05 Jun, 15:00 · core
0.36
Implementing a 22-step WebAuthn validation flow is hard - even for co-authors of the spec. At #BHUSA, I'll be presenting "Pass-the-Passkey": a new family of attacks bypassing phishing-resistant MFA. Replay. Relay. Tamper. Spoof. 3 new vulns. 20 attacks. 5 OSS tools. #BHUSA will b
tweet media
@SpecterOps avatar
SpecterOps @SpecterOps
05 Jun, 18:10 · core
0.34
And the winner is... foobar! At the close of #InfoSecEurope, foobar was crowned the #BloodHoundUnleashed Attack Path Champion! Thank you to all of our competitors for your enthusiasm and participation throughout the challenge. We will see you for the next one...
tweet media
@_JohnHammond avatar
_JohnHammond @_JohnHammond
06 Jun, 19:50 · secondary
0.29
PS PS PS, http:// OnlyLANs.ai launched yesterday during our first-week-of-the-month livestream, where we also released Dahvid's Schloss latest training: Windows Malware Development 6: Building Post Exploitation Tools! https:// justhacking.com/course/wmd-6-b uilding-post-exploitat
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
05 Jun, 20:12 · core
0.28
Favorite queries! Log in, heart the queries you use most, sort for Most Favorites, and use Show Favorites to filter your list. For now, this applies to the BloodHound Query Library source. 5/6
tweet media
@SpecterOps avatar
SpecterOps @SpecterOps
05 Jun, 20:12 · core
0.28
Happy #BloodHoundBasics Day! This week, @martinsohndk walks through: http:// queries.specterops.io helps you find & run the queries you need. Caught up on the latest features? - Multi-source loading - Multi-server management - Favorites - Cypher cheat sheet Quick glance in 1/6
tweet media
@mrgretzky avatar
mrgretzky @mrgretzky
05 Jun, 18:39 · core
0.28
New Release Havoc Professional 0.7: K-Noir - Linux Implant for x86_64 and AArch64 - Stack Spoofing: Callstack Function Rule System - Stack Spoofing: CET Compliance and evasion improvements. - New Registry manipulation extension with anti-forensic features - TCP based
tweet media

Regular sources

5 items
1.00general · 05 Jun, 18:46microsoft.comAttack pathResearch

Securing CI/CD in an agentic world: Claude Code Github action case

Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This …

1.00critical · 05 Jun, 14:00cisa.govWild exploit

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-28318 SolarWinds Serv-U Unc…

0.91general · 05 Jun, 16:00bleepingcomputer.comAttack path

What 2026 DBIR Confirms: Attacks Are Living in the Browser

Phishing, shadow AI, malicious extensions, and credential theft increasingly happen inside the browser. Keep Aware explains what the 2026 Verizon DBIR reveals about brow…

0.89exploit · 05 Jun, 02:16seclists.org

[REVIVE-SA-2026-002] Revive Adserver Vulnerabilities

Posted by Matteo Beccati on Jun 04 ======================================================================== https://www.revive-adserver.com/security/revive-sa-2026-002 -…