HAIJA INTEL REPORT
Tweets / X
8 items












Regular sources
7 itemsWeek in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has …
croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)
Posted by Souiri Anas on Aug 14 Hello, This reports an arbitrary file deletion vulnerability in croc, the end-to-end encrypted file transfer tool [1], which can be chain…
How Cloudflare detects MCP traffic and helps secure it
Cloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce Portal-only access for…
Hackers Exploiting Unpatched GeoServer Zero-Day
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Da…
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security expl…
Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged userns
Posted by Erica Windisch on Aug 16 Erica ---------- Forwarded message --------- From: Erica Windisch Date: Sun, Aug 16, 2026 at 2:31 PM Subject: OpenZFS Linux open zpool…
IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)
Posted by Bakabaka_9 on Aug 14 Hi, In IXP Manager (tested on v7), an authenticated user with at least AUTH_CUSTUSER privileges can update or delete arbitrary API key rec…