Official intelligence summary

HAIJA INTEL REPORT

Generated 30/07/2026, 09:40. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources2
Tweets / X13
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

13 items
@mrgretzky avatar
mrgretzky @mrgretzky
29 Jul, 11:43 · core
0.50
Excited to be back as a @defcon mainstage speaker in Vegas for the 2nd year in a row! This year I'll reveal new techniques to get Microsoft to deliver any phishing email from official Microsoft addresses. Plus... interactive phishing pages rendered inside email clients!?
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
29 Jul, 18:04 · core
0.40
Who can actually assume that role? Who can reach your secrets, keys, or data? @hotnops explores how BloodHound Enterprise brings the attack path mindset to AWS to answer those questions.
@Rapid7 avatar
Rapid7 @Rapid7
29 Jul, 19:01 · secondary
0.35
On 7/27/26, #JetBrains published a security advisory for CVE-2026-63077, a critical vuln. affecting all versions of TeamCity On-Premises. Attackers who exploit the vulnerability can read stored credentials and compromise CI/CD pipeline integrity. More: https:// r-7.co/4h3tVFR
tweet media
@Jhaddix avatar
Jhaddix @Jhaddix
29 Jul, 19:52 · core
0.34
The AI didn't magically escape the network. It found the same exposed secrets, flat networks, overprivileged service accounts, and forgotten admin portals we've been documenting in pentest reports for the last decade. Apparently those findings only became urgent once the attacker
@TalosSecurity avatar
TalosSecurity @TalosSecurity
29 Jul, 14:46 · secondary
0.34
Cisco Talos Incident Response’s Q2 trends report is out. Author Lexi DiScola joins Amy to show you exactly how attackers are evolving and the practical steps you can take to stop them: https:// cs.co/6016BEatZw
tweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
29 Jul, 21:04 · core
0.32
AI won't affect the bug bounty https:// coinbase.com/blog/focusing- our-bug-bounty-program-on-what-matters-most-in-the-age-of-ai …
tweet mediatweet media
@Jhaddix avatar
Jhaddix @Jhaddix
29 Jul, 18:17 · core
0.32
just remember the AI hackbot training corpus wouldn't exist without the research and hacking community at cons like @BlackHatEvents & @defcon (and all other cons) keep researching, keep learning, keep hacking... it's gonna be ok.
@nahamsec avatar
nahamsec @nahamsec
29 Jul, 15:01 · core
0.32
We at @pdiscoveryio are looking to hire a cracked security researcher. priority on heavy CTF background & pure research experience over standard bug bounty work. need high agency, total ownership, zero hand-holding. looking for the absolute best in the game. DMs are open
@albinowax avatar
albinowax @albinowax
29 Jul, 13:45 · core
0.32
Come and see @m4st3rspl1nt3r and I present "CRLF-Powered Desync Attacks: Beheading HTTP Streams" at @BlackHatEvents and @defcon next week! We cannot wait to share what we've found! In less than 2 weeks @t0xodile and I will present "CRLF-Powered Desync Attacks: Beheading HTTP Stre
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
29 Jul, 02:06 · core
0.32
Started tracking the new mini-articles I’m posting to socials on my blog at https:// blog.xpnsec.com/articles Hopefully helps to keep track of what was posted where
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
29 Jul, 23:13 · core
0.28
Compromise one node in a Windows Server Failover Cluster and you've compromised all of them. @unsigned_sh0rt dug into why: shared credentials, forged tickets, and a full attack chain to own the cluster. Check it out!
tweet media
@vxunderground avatar
vxunderground @vxunderground
29 Jul, 23:09 · secondary
0.24
Hi I've uploaded another 150,000 malwares to the internet. I haven't pushed the update file yet, but the malware is there for you to download and enjoy. If you need anything please contact me secretary (homeless guy at the gas station) Cheers, Pic unrelated
tweet mediatweet media
@CrowdStrike avatar
CrowdStrike @CrowdStrike
29 Jul, 21:14 · secondary
0.24
Every cloud change creates a new security decision. This month’s Falcon Cloud Security release reduces operational effort so your team can move faster. IaC security in VS Code & IntelliJ Custom Rego Rules 1-click CIEM remediation Agentless Azure VM Scanning K8s
tweet mediatweet media

Regular sources

2 items
1.00general · 29 Jul, 17:39thehackernews.comRCE

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that coul…

1.00general · 29 Jul, 10:58thehackernews.comPoC

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and M…