Official intelligence summary

HAIJA INTEL REPORT

Generated 12/06/2026, 09:18. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources3
Tweets / X12
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

12 items
H4
h4x0r_dz @h4x0r_dz
11 Jun, 22:01 · core
0.72
Unauthenticated attackers are gaining SYSTEM on domain controllers with crafted packets. The vulnerability being exploited is CVE-2026-41089, a CVSS 9.8 hole in Windows Netlogon, and exploitation in the wild has been co…
@SpecterOps avatar
SpecterOps @SpecterOps
11 Jun, 22:21 · core
0.60
Want to better defend Azure and Entra ID environments? Start by understanding the adversary's perspective. At #BHUSA, our Azure training uses hands-on labs to teach the attack paths, misconfigs, and techniques used against modern cloud environments. https:// ghst.ly/4uii3Ua
tweet mediatweet media
MA
Mandiant @Mandiant
11 Jun, 22:30 · secondary
0.49
ShinyHunters is exploiting an Oracle PeopleSoft vulnerability (CVE-2026-35273) as part of an extortion campaign targeting higher education. Read the full analysis, and get IOCs and remediation guidance to stay ahead of …
@_dirkjan avatar
_dirkjan @_dirkjan
11 Jun, 23:05 · core
0.46
just wrapped up @OutsiderSec ’s Offensive Entra ID training with @_dirkjan . He is in fact #thegoat it was literally the best Entra ID training going into the nitty gritty details including agent identity blueprints
tweet mediatweet media
@Rapid7 avatar
Rapid7 @Rapid7
11 Jun, 15:26 · secondary
0.42
AI is actively embedding itself into today's criminal tradecraft - lending itself to social engineering, fraud, impersonation, identity abuse & more. Get to know tools like WormGPT and BruteforceAI, plus, how orgs should react, all in a new blog: https:// r-7.co/4ooQFS7
tweet mediatweet media
@Mandiant avatar
Mandiant @Mandiant
11 Jun, 00:00 · secondary
0.41
ICYMI: Mandiant identified exploitation of a critical vulnerability in KnowledgeDeliver, a learning management system commonly used in Japan. The vulnerability allows for unauthenticated remote code execution via ViewState deserialization. Details: https:// goo.gle/444QSjW
tweet mediatweet media
@brutelogic avatar
brutelogic @brutelogic
11 Jun, 16:24 · secondary
0.38
Broken Token: OAuth New ebook, 2nd of the series. Master every way to break OAuth flow: PKCE downgrade DCR injection Token lifecycle abuse Grant flow weaponization + 13 original named techniques https:// brutelogic.net/ebooks/broken- token/oauth/ … The most complete offensive OAu
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
11 Jun, 11:44 · core
0.32
A little bit different than in the movies AI research at the gym
tweet mediatweet media
@ShitSecure avatar
ShitSecure @ShitSecure
11 Jun, 16:43 · curator
0.25
Releasing DCOMIllusionist as part of our talk on DCOM at @x33fcon with @k3vinTell . It's a remote in memory fileless lateral movement technique based on some research of @tiraniddo
tweet media
@_JohnHammond avatar
_JohnHammond @_JohnHammond
11 Jun, 21:16 · secondary
0.24
Long live Active Directory! I’m giving a talk for ContinuumCon tomorrow (Friday June 12th) at 1:30pm eastern. Killing AD attack paths by using auth policies & silos.
tweet mediatweet media
@Synack avatar
Synack @Synack
11 Jun, 20:34 · secondary
0.24
What questions should security teams ask before adopting AI pentesting? According to our CTO and co-founder @MarkKuhr , the right framework is less about model benchmarks and more about three things: access, governance, and validation: https:// hubs.ly/Q04l5bSY0 #aipentesting
tweet mediatweet media
@vxunderground avatar
vxunderground @vxunderground
11 Jun, 19:45 · secondary
0.24
Hello, If you're a person who lives inside my computer and/or likes malware and/or goes to computer conventions, I have a message for you. tl;dr 1. idk if going to defcon, stop asking fr 2. vxug party? idfk 3. big giveaway thingy 4. defcon shirts ig idfk 5. papers non-tl;dr
tweet mediatweet media

Regular sources

3 items
1.00general · 11 Jun, 15:37research.checkpoint.comRCEResearch

From SQLi to RCE - Exploiting LangGraph’s Checkpointer

By Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers - persistence layers that store execution state. But what happens when …

1.00general · 11 Jun, 11:56securityweek.comPoC

‘GreatXML’ Zero-Day Exploit Bypasses BitLocker

The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appea…

0.86critical · 11 Jun, 14:00cisa.gov

Naxclow IoT Platform

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to impersonate devices, intercept or manipulate communications, harvest sensit…