Official intelligence summary

HAIJA INTEL REPORT

Generated 26/08/2026, 09:42. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources5
Tweets / X10
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

10 items
@SpecterOps avatar
SpecterOps @SpecterOps
25 Aug, 16:09 · core
0.68
Happening TODAY! Join @jaredcatkinson & @JustinKohler10 at 1pm ET/10am PT for a discussion into Identity Attack Path Management in AWS, Entra Agent ID support, agentic AI security & the growing OpenGraph ecosystem. https:// ghst.ly/4h0yWPn
tweet mediatweet media
@brutelogic avatar
brutelogic @brutelogic
25 Aug, 16:26 · secondary
0.55
Break and Bypass - Tasting Menu Comment & Jump Technique UNION--%0ASELECT Info Disclosure Easy Wins /.git /.env /server-status /swagger.json SSRF Polyglot for Filters http://trusted.com@0177.0.0.1#@trusted.com JWT jku Trust Abuse Brute Bundle AfterMath Statistical, Broken Token J
tweet media
@SpecterOps avatar
SpecterOps @SpecterOps
25 Aug, 00:56 · core
0.34
Red teaming should produce findings security leaders can act on. @ne0nd0g , @andrewchiles & @_xpn_ will discuss aligning engagements to business risk, the impact of assumed breach & the difference between measuring and building detection & response. https:// ghst.ly/4qAYKEj
tweet mediatweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
25 Aug, 11:31 · core
0.32
Doing vulnerability research & bug bounty using LLMs is like gambling.
tweet mediatweet media
@vxunderground avatar
vxunderground @vxunderground
25 Aug, 18:37 · secondary
0.24
I made some typos, I meant to say "more technical for nerds", and when I copied the C2 addresses for ILSpy I messed up the formatting. This was actually a kind of annoying payload to reverse because everything was so absurdly bloated and filled with junk. Anyway, that's what
tweet media
@intigriti avatar
intigriti @intigriti
25 Aug, 11:03 · secondary
0.24
Logic flaws are among the most underrated bug classes in bug bounties, as they usually remain undetected by scanners! From bypassing payment flows and exploiting race conditions to abusing permission profiles and manipulating multi-step workflows! Our guide covers how
tweet mediatweet media
@vxunderground avatar
vxunderground @vxunderground
25 Aug, 07:03 · secondary
0.24
If you're going to distribute malware, at least have the common courtesy to do it in a manner which allows EVERYONE to get the malware. Last time on Dragon Ball Z: I got over 9,000 DMs about a GTA VI video game leak circulating on torrent sites. Truthfully, I'm not up to date on
@vxunderground avatar
vxunderground @vxunderground
25 Aug, 02:08 · secondary
0.24
When you have malware on your computer, and you let your anti-virus remove it, this is who you're hurting. Happy now? Don't remove the malware. Malware is good
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
25 Aug, 22:53 · core
0.20
ICYMI: @_wald0 , @harmj0y & @CptJesus joined #KnowYourAdversary to take a look back at 10 years of BloodHound! Tune in & hear about how BloodHound has evolved in the years since it was first unveiled at #DEFCON in 2016. Listen to both parts https:// ghst.ly/3Kkoiob
tweet media
@TheDFIRReport avatar
TheDFIRReport @TheDFIRReport
25 Aug, 18:05 · core
0.20
Tool Tuesday: Rclone A legitimate tool for backing up and syncing data to the cloud, which is exactly why threat actors reach for it to steal yours. In our investigations, actors drop Rclone (often renamed) to exfiltrate gigabytes to MEGA, SFTP, or FTP just before ransomware.
tweet mediatweet media

Regular sources

5 items
1.00general · 25 Aug, 17:00blog.gitguardian.comResearch

Agentic AI Security: Credentials and Permissions Define the Blast Radius

Prompt injection can't be patched away. Three 2026 agentic AI incidents show that credentials and permissions decide the damage.

1.00general · 25 Aug, 16:01helpnetsecurity.com

INTERPOL crackdown on West African crime rings uncovers troubling new trend

Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspect…

1.00critical · 25 Aug, 14:00cisa.govRCE

Zoneminder

View CSAF Summary Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zonemi…

1.00general · 25 Aug, 13:52thehackernews.comAttack path

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-sty…

0.89exploit · 25 Aug, 23:57seclists.org

[vim-security] Arbitrary Ex Command Execution via File Names in C Omni-Completion in Vim < 9.2.1011

Posted by Christian Brabandt on Aug 25 Arbitrary Ex Command Execution via File Names in C Omni-Completion in Vim < 9.2.1011 =============================================…