
HAIJA INTEL REPORT
Tweets / X
6 items







Regular sources
9 itemsThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malw…
CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Posted by Charles Zhang on Aug 20 Severity: important https://github.com/apache/inlong/pull/12146 . Credit: dyingman1 (finder) References:...
rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv)
Posted by Rainer Gerhards on Aug 20 Hello, https://github.com/rsyslog/rsyslog/security/advisories/GHSA-xmp9-244p-5ggv The affected area is omfile configurations that use…
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that …
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team…
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse…
[0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8)
Posted by disclosure via Fulldisclosure on Aug 19 0day Rubbish Research Team is publicly disclosing a vulnerability in VMS 6.48.809. Type: Authenticated command injectio…
[0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8)
Posted by disclosure via Fulldisclosure on Aug 19 0day Rubbish Research Team is publicly disclosing a vulnerability in ONE Reporter 13.1. Type: Authenticated RCE / privi…
[0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8)
Posted by disclosure via Fulldisclosure on Aug 19 0day Rubbish Research Team is publicly disclosing a vulnerability in Gemini 7.3.0. Type: Authenticated SQL injection to…