Official intelligence summary

HAIJA INTEL REPORT

Generated 15/06/2026, 09:18. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources4
Tweets / X11
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

11 items
@Jhaddix avatar
Jhaddix @Jhaddix
12 Jun, 17:02 · core
0.58
We've all been there. A major breach drops and you're piecing together the story from a dozen different sources. The GitHub/TeamPCP incident is a perfect example. ~3,800 internal repos exfiltrated, LAPSUS$ involved as the monetization arm, a supply chain campaign that had been
tweet media
@Jhaddix avatar
Jhaddix @Jhaddix
13 Jun, 05:04 · core
0.56
Sucky outcome but not untrue. Muti-turn model forcing, several evasions, context overload, and a verbatim jailbreak by BT6 and @elder_plinius were all going around. They all illustrated the ability of the model to do simple exploitation, but every demonstration I saw to do
tweet mediatweet media
UN
Unit42_Intel @Unit42_Intel
12 Jun, 21:13 · secondary
0.56
Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sec…
@vxunderground avatar
vxunderground @vxunderground
14 Jun, 20:21 · secondary
0.45
This is a tricky question and, in a bit of irony, there is a kind of like ... an unspoken ... or poorly documented philosophy of malware development. You kind of learn tricks of the trade as you write malware and witness malware campaigns operating in the wild. tl;dr idk it what
@_xpn_ avatar
_xpn_ @_xpn_
13 Jun, 14:43 · core
0.42
Wall Street Journal is reporting that Amazon reported the jailbreaks to the Department of Commerce, who instituted the ban
tweet media
@Jhaddix avatar
Jhaddix @Jhaddix
12 Jun, 17:06 · core
0.40
I’m once again here to tell you that *most* bug bounty platforms will or have used your hunting data in AI endeavors. bug bounty as an enterprise strategy is much lower margin than AI security. Or they will use it for auto triage. Which then they will conveniently forget
@brutelogic avatar
brutelogic @brutelogic
13 Jun, 16:35 · secondary
0.36
This Week on BRute Logic JWT Auth Bypass TestBed https:// x.com/BRuteLogic/sta tus/2063970745504371053 … Brute One v0.2 with JBroken https:// x.com/BRuteLogic/sta tus/2064359531522535477 … Crack Me Challenge https:// x.com/BRuteLogic/sta tus/2064722656599892121 … New Ebook - Brok
tweet mediatweet media
@mrgretzky avatar
mrgretzky @mrgretzky
12 Jun, 17:55 · core
0.36
Very happy the Google phishing live demo was a success after the internet connection suddenly stopped working briefly on stage. Demo gods today tried to play some tricks. #Evilginx is back this year at #x33fcon, @mrgretzky is presenting "Downgrading #FIDO #MFA With #AI Slop" - #r
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
12 Jun, 17:48 · core
0.36
Talk is over and reel is finally public. https:// github.com/trustedsec/Reel #x33fcon "Towards Continuous #Social #Engineering" talk by @two06 - https:// x33fcon.com/#!/s/JamesWill iams.md … - #red, #demo, #social_engineering
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
14 Jun, 22:40 · core
0.34
And there we go, digital id… fuck sake!! NEW: The UK social media ban for under-16s will be enforced through facial recognition, digital IDs, credit cards, open banking, passports, mobile provider checks or email age estimation
@_JohnHammond avatar
_JohnHammond @_JohnHammond
14 Jun, 18:29 · secondary
0.32
Matthew Nguyen starting the party for ContinuumCon Day 3, walking us through using Malcat (), FakeNet, and more for some sweet malware analysis! https:// continuumcon.com Workshop Spotlight #8 "How to Analyze Malware" by Matthew Nguyen Description A practical introduction to malw
tweet mediatweet media

Regular sources

4 items
1.00general · 14 Jun, 10:00helpnetsecurity.com

Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an O…

1.00exploit · 14 Jun, 00:35seclists.org

Re: Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)

Posted by Solar Designer on Jun 13 Hi David, Thank you for bringing this up. I do indeed see the problem, but I don't like the proposal. Also, for now the increased volu…

1.00general · 12 Jun, 11:50thehackernews.comRCE

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in r…

1.00general · 12 Jun, 07:40helpnetsecurity.com

ZeroFox releases AI Analytics to bring answers directly to security teams

ZeroFox launched ZeroFox AI Analytics, a new platform capability that gives security teams real-time visibility into the signals, patterns, and trends shaping their exte…