
HAIJA INTEL REPORT
Tweets / X
6 items







Regular sources
9 itemsgraphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via per-error full-document rescan (GetLocation)
Posted by First name Last name on Aug 26 Hello, This reports an algorithmic-complexity denial-of-service defect in github.com/graphql-go/graphql, affecting all released …
[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
Posted by advisories on Aug 26 ---------------------------------------------------------------------------- NotCVE Advisory - NotCVE-2026-0010 --------------------------…
WatsonWebserver v7.1.0 HTTP/1 Chunked Request Processing Bypasses MaxRequestBodySize
Posted by Ron E on Aug 26 WatsonWebserver contains an HTTP/1 request body size-limit bypass when processing requests using Transfer-Encoding: chunked. The framework's co…
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat i…
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw imp…
AI vulnerability discovery scores the highest impact of 20 emerging risks
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came …
Why Your AI Application Is Exposed Snyk
AI applications can pass security scans yet remain exploitable through chained attacks across models, tools, data, and business workflows. Learn how DAST, AI pentesting,…
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft…
Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosure
Posted by Ron E on Aug 26 An unauthenticated remote debugger vulnerability exists in Escargot v4.3.0-214-gfaee4437 when the application is compiled with ESCARGOT_DEBUGGE…