Official intelligence summary

HAIJA INTEL REPORT

Generated 21/08/2026, 09:41. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources9
Tweets / X6
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

6 items
@_dirkjan avatar
_dirkjan @_dirkjan
20 Aug, 10:13 · core
0.60
The next edition of my offensive Entra ID security class just opened up for registration! November 16-19 in The Hague, Netherlands. In this 4 day class we deep dive into Entra ID security, tokens, oauth2 and Conditional Access. More info and reg:
tweet media
@Mandiant avatar
Mandiant @Mandiant
20 Aug, 05:25 · secondary
0.49
Voice phishing (vishing) has surged to become the second most common initial infection vector globally. All employees need to be ready to spot and report live-call social engineering before an attacker gains a foothold. Learn more in M-Trends 2026 https:// goo.gle/4gG3uoO
tweet media
@BishopFox avatar
BishopFox @BishopFox
20 Aug, 23:46 · secondary
0.34
One prompt was blocked, but we don't stop! In this clip from Where AI Breaks: Field Notes from GenAI and Agentic Testing (now on demand), Derek Rush explains how a real AI assessment escalated from prompt injection to Azure access.
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
20 Aug, 22:48 · core
0.34
Kubernetes security is often treated as isolated findings. But how do they connect? Kubernetes for Red Teamers uses hands-on labs to explore how insecure defaults & misconfigs across access, identity & boundaries can form attack paths. Get started: https:// ghst.ly/3TVMxhp
tweet mediatweet media
@TheDFIRReport avatar
TheDFIRReport @TheDFIRReport
20 Aug, 15:02 · core
0.34
"The initial payload named BC_invoice_Report_CORP_46.iso, is an ISO image that once mounted, lures the user to open a document.lnk file which will execute the malicious DLL loader using the following command line:." Read the full report: https:// buff.ly/2KNoCzc #DFIR
tweet mediatweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
20 Aug, 12:42 · core
0.34
CVEs everywhere 0days everywhere RCEs everywhere And yet I still see some posts say AI won't affect cybersecurity

Regular sources

9 items
1.00general · 20 Aug, 19:23thehackernews.comRCE

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malw…

1.00exploit · 20 Aug, 18:11seclists.org

CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path

Posted by Charles Zhang on Aug 20 Severity: important https://github.com/apache/inlong/pull/12146 . Credit: dyingman1 (finder) References:...

1.00exploit · 20 Aug, 15:57seclists.org

rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv)

Posted by Rainer Gerhards on Aug 20 Hello, https://github.com/rsyslog/rsyslog/security/advisories/GHSA-xmp9-244p-5ggv The affected area is omfile configurations that use…

1.00general · 20 Aug, 15:48thehackernews.comRCE

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that …

1.00general · 20 Aug, 15:24thehackernews.comRCEWild exploit

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team…

1.00general · 20 Aug, 12:00unit42.paloaltonetworks.comAttack path

Identity Abuse Through Trusted Communication Channels

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse…

1.00exploit · 20 Aug, 08:25seclists.orgRCEResearch

[0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8)

Posted by disclosure via Fulldisclosure on Aug 19 0day Rubbish Research Team is publicly disclosing a vulnerability in VMS 6.48.809. Type: Authenticated command injectio…

1.00exploit · 20 Aug, 08:25seclists.orgRCETradecraftResearch

[0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8)

Posted by disclosure via Fulldisclosure on Aug 19 0day Rubbish Research Team is publicly disclosing a vulnerability in ONE Reporter 13.1. Type: Authenticated RCE / privi…

1.00exploit · 20 Aug, 08:25seclists.orgRCEResearch

[0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8)

Posted by disclosure via Fulldisclosure on Aug 19 0day Rubbish Research Team is publicly disclosing a vulnerability in Gemini 7.3.0. Type: Authenticated SQL injection to…