Official intelligence summary

HAIJA INTEL REPORT

Generated 09/06/2026, 09:19. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources3
Tweets / X12
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

12 items
@SpecterOps avatar
SpecterOps @SpecterOps
08 Jun, 21:17 · core
0.46
AzureHound now has least-privilege permission documentation + @martinsohndk shows the internal research that made it. TL;DR of changes: http:// Directory.Read.All → 8 MS Graph permissions Reader role → 16 ARM actions Directory Readers → not required https:// ghst.ly/4vzI8yk
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
08 Jun, 21:14 · core
0.46
What kind of bugs ? *ANTHROPIC TESTING CONFIRMS MYTHOS SUCCESSFULLY EXPLOITED 18 OF 21 WINDOWS KERNEL BUGS DISCLOSED RECENTLY *ANTHROPIC RESEARCH SHOWS MYTHOS EXPLOITS WINDOWS KERNEL FLAWS AT A COST OF $2,000 EACH *ANTHROPIC'S MYTHOS MODEL CREATES WORKING CYBER EXPLOITS FROM PUBL
@RedCanary avatar
RedCanary @RedCanary
08 Jun, 20:41 · secondary
0.38
Assistive AI agents aren’t always so helpful - it all depends on whose behalf they're working. The final installment of our series on suspicious AI workflows in Microsoft Entra ID highlights an "on behalf of" authentication workflow. Take a look at the logs:
tweet media
@SentinelOne avatar
SentinelOne @SentinelOne
08 Jun, 21:07 · secondary
0.25
$100K. One world title. 400+ flags pulled from live attack campaigns. Your move. The Threat Hunting World Championship 2026 opened June 2. Compete against threat hunters around the world in brand-new 30-minute capture-the-flag rounds. The Top 200 players per region will
tweet media
@RedCanary avatar
RedCanary @RedCanary
08 Jun, 22:05 · secondary
0.24
If your tech stack is a force multiplier, but your “human tool” is at zero, what exactly are you multiplying? Join Keith McCammon and Katie Nickels live on SecOps Weekly to hear how to lead your SOC team through the anxiety of the agentic AI shift - and how better
tweet media
@Synack avatar
Synack @Synack
08 Jun, 21:33 · secondary
0.24
That’s a wrap on #GartnerSEC 2026! From whiskey tasting to theater sessions to rolling dice at our booth, the energy was unmatched! Huge thanks to everyone who stopped by to chat about the future of cybersecurity! #AIPentesting #Synack #InfoSec
tweet mediatweet media
@Bugcrowd avatar
Bugcrowd @Bugcrowd
08 Jun, 20:08 · secondary
0.24
We just launched an EU data residency option to help organizations manage their evolving data sovereignty and compliance needs. This update allows customers to store and process their crowdsourced security data entirely within the European Union. As data privacy
tweet media
@CrowdStrike avatar
CrowdStrike @CrowdStrike
08 Jun, 20:06 · secondary
0.24
Adversaries aren't slowing down. Are you keeping up? 27-second breakout times 89% increase in AI-enabled attacks 82% of intrusions are malware-free The threat landscape has changed. Has your defense strategy? Watch the full video: https:// crwdstr.ke/6014B8LHu8
tweet media
@BishopFox avatar
BishopFox @BishopFox
08 Jun, 22:42 · secondary
0.22
Sparkplug B is widely used across ICS and SCADA environments. Until now, there wasn’t a publicly available security fuzzer built for it. New research from David Colón and Shad Malloy explores how they built a Sparkplug B fuzzer covering all 9 message types, all 19 data types,
tweet mediatweet media
@pdiscoveryio avatar
pdiscoveryio @pdiscoveryio
08 Jun, 16:16 · secondary
0.22
@pdiscoveryio has had a huge impact on the bug bounty community with tools like Nuclei, Httpx, Katana, Subfinder, Naabu, and many more. But beyond the popular tools, they have built several lesser-known gems that can make recon, validation, and vulnerability research much
tweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
08 Jun, 23:22 · core
0.20
We going to have The worst World cup version ever Named by FIFA to officiate during the World Cup, the Somali referee Omar Artan was denied entry to U.S. territory Due to his difficulties in obtaining a visa, he had benefited from the support of the Somali embassy in Nairobi, whi
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
08 Jun, 23:17 · core
0.20
Pretty sure this is how Skynet started! Siri AI can now create reminders and start timers
tweet media

Regular sources

3 items
1.00general · 08 Jun, 15:18thehackernews.com

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More

Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic t…

1.00general · 08 Jun, 14:16securityweek.comWild exploit

Everest Forms Vulnerability Exploited to Hack WordPress Sites

The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack Wo…

0.89exploit · 08 Jun, 08:27seclists.org

rsync 3.4.4 released, regression fixes

Posted by Andrew Tridgell on Jun 07 I've released rsync 3.4.4 which has regression fixes for the rsync 3.4.3 https://rsync.samba.org/ - it is not embargoed as it contain…