
HAIJA INTEL REPORT
Tweets / X
10 items











Regular sources
5 itemsSecuring CI/CD in an agentic world: Claude Code Github action case
Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This …
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-28318 SolarWinds Serv-U Unc…
Re: HTTP/2 Bomb affects Apache httpd, nginx, envoy, & pingora
Posted by Alan Coopersmith on Jun 04 Additional patches have since been released by envoy & h2o. https://github.com/envoyproxy/envoy/security/advisories/GHSA-22m2-hvr2-x…
What 2026 DBIR Confirms: Attacks Are Living in the Browser
Phishing, shadow AI, malicious extensions, and credential theft increasingly happen inside the browser. Keep Aware explains what the 2026 Verizon DBIR reveals about brow…
[REVIVE-SA-2026-002] Revive Adserver Vulnerabilities
Posted by Matteo Beccati on Jun 04 ======================================================================== https://www.revive-adserver.com/security/revive-sa-2026-002 -…