HAIJA INTEL REPORT
Tweets / X
8 items









Regular sources
7 itemsOpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found e…
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote …
CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]
Re: Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely
Posted by Greg KH on Aug 26 Ah, I'm talking to a bot {sigh} The "squabbling" happens with people, and I think I'll stop responding here as this isn't going to go very we… | Posted by Syed on Aug 26 https://www.google.com/url?q=http://cve.org&source=gmail&ust=1787893426670000&sa=E json records are known to have this issue, because almost Fai…
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the wee…
Rockwell Automation OTTO Fleet Manager
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks again…
Applied Systems Engineering ASE2000 V2 Communications Test Set
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outboun…