Official intelligence summary

HAIJA INTEL REPORT

Generated 17/08/2026, 09:38. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources7
Tweets / X8
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

8 items
TH
TheDFIRReport @TheDFIRReport
14 Aug, 15:15 · core
0.76
Private DFIR Report: ViewState of Mind, Gladinet Exploit Opens the Door In January, a threat actor gained initial access by exploiting CVE-2025-30406 on an exposed Gladinet CentreStack server, large VIEWSTATE payloads i…
@SpecterOps avatar
SpecterOps @SpecterOps
14 Aug, 23:28 · core
0.62
Don’t forget to save your spot for our upcoming webinar! Join @jaredcatkinson & @JustinKohler10 to explore Identity Attack Path Management in AWS, Entra Agent ID support, agentic AI security & the growing OpenGraph ecosystem. https:// ghst.ly/4h0yWPn
tweet mediatweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
15 Aug, 22:07 · core
0.54
We just released our uncensored weights for Qwen3.8 27B FP8, designed for AI Red Teaming and security research, enjoy! https:// huggingface.co/orcarouter/Qwe n3.8-27B-Uncensored-FP8 …
tweet media
@brutelogic avatar
brutelogic @brutelogic
15 Aug, 16:35 · secondary
0.50
This Week on BRute Logic Bash RCE Bypass Tricks https:// x.com/BRuteLogic/sta tus/2086821872134750404 … Brute Bundle - All ebooks $99 https:// x.com/BRuteLogic/sta tus/2087179979746369821 … Testbeds - XSS, Recon, 403, JWT, OAuth https:// x.com/BRuteLogic/sta tus/20871845752774374
tweet mediatweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
14 Aug, 21:20 · secondary
0.41
Since March 2026, we have tracked ENIBot, a rapidly expanding Mirai-derived IoT botnet, capturing 7,504 unique bot IPs globally. The campaign escalated brute-force and ADB exploitation attacks through June and July. Details at https:// bit.ly/3UepRJh
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
14 Aug, 19:11 · core
0.40
We're back with a new #BloodHoundBasics post from @SadProcessor ! Ready to take your #BloodHound skills to the next level? Head over to the SpecterOps Tradecraft Academy and dive into our free BloodHound Basics Workshop. (1/4)
tweet mediatweet media
@CrowdStrike avatar
CrowdStrike @CrowdStrike
14 Aug, 20:23 · secondary
0.35
Frontier AI security benchmarks have a blind spot. Most focus on vulnerability discovery. But that's only one piece of an adversary's playbook. Today's attacks rely on identity abuse, phishing, social engineering, trusted relationships, and hands-on-keyboard activity after
tweet mediatweet media
@outflanknl avatar
outflanknl @outflanknl
14 Aug, 18:01 · core
0.28
See which way the wind is blowing at Outflank! Every gust brings something new and moves OST forward. Join us on August 24th for a live demo of Outflank Security Tooling, including the latest additions to our evasive red teaming toolset. Register now: https:// ow.ly/xKhj50Zzx2k
tweet mediatweet media

Regular sources

7 items
1.00general · 16 Aug, 10:00helpnetsecurity.com

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has …

1.00exploit · 14 Aug, 17:262 mentionsseclists.orgRCE

croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)

Posted by Souiri Anas on Aug 14 Hello, This reports an arbitrary file deletion vulnerability in croc, the end-to-end encrypted file transfer tool [1], which can be chain…

1.00general · 14 Aug, 15:12blog.cloudflare.comResearch

How Cloudflare detects MCP traffic and helps secure it

Cloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce Portal-only access for…

1.00general · 14 Aug, 09:01securityweek.comRCE

Hackers Exploiting Unpatched GeoServer Zero-Day

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Da…

0.91general · 14 Aug, 16:00bleepingcomputer.comAttack path

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security expl…

0.89exploit · 16 Aug, 22:44seclists.org

Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged userns

Posted by Erica Windisch on Aug 16 Erica ---------- Forwarded message --------- From: Erica Windisch Date: Sun, Aug 16, 2026 at 2:31 PM Subject: OpenZFS Linux open zpool…

0.89exploit · 14 Aug, 16:27seclists.org

IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)

Posted by Bakabaka_9 on Aug 14 Hi, In IXP Manager (tested on v7), an authenticated user with at least AUTH_CUSTUSER privileges can update or delete arbitrary API key rec…