Official intelligence summary

HAIJA INTEL REPORT

Generated 07/09/2026, 10:06. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources9
Tweets / X6
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

6 items
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
06 Sept, 12:15 · core
0.66
MikroTik ssh 0day 👀 Heads up, there is a 1-day full MikroTik RCE chain against SSH being used in the wild. Patch was released yesterday, so if you have a MikroTik router with ssh open on the internet, it may already be compromised. Detection guidance and IOCs courtesy of @CERT_P
tweet media
@TheDFIRReport avatar
TheDFIRReport @TheDFIRReport
04 Sept, 18:10 · core
0.66
🧪 DFIR Labs | ClickFix / RomComRAT, Private Case #35646 A fake-CAPTCHA (ClickFix) lure kicks off a nine-day espionage operation. Follow custom RomComRAT implants, stealthy lateral movement, credential harvesting, and a massive data-theft campaign that ends in domain compromise.
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
04 Sept, 20:08 · core
0.34
The Posture PDF Export feature allows you to export your attack path exposure history to a PDF file. After enabling it, you will see a new button appear in your Posture page. 🧵: 2/3
tweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
04 Sept, 17:30 · secondary
0.34
We investigated a breach where autonomous AI agents executed an intrusion in under 10 hours, compressing weeks of tradecraft. The actor mapped networks, seized root credentials and left an AI-generated report. Explore our full investigation: https:// bit.ly/4iKWXe2
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
06 Sept, 16:04 · core
0.32
Aw that’s a cute email from @CloudflareDev , only moved the blog over end of July, 858,147 page views since I moved over! Netlify never sent me any achievement emails 🤨🤣
tweet mediatweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
05 Sept, 00:36 · secondary
0.29
Unit 42 has identified VoidShadow, a modular cross-platform (#Linux + #Windows) implant for full remote control & credential theft. It disguises #C2 as #MicrosoftGraph, #WordPress & #GoogleCloud traffic and hides via userland + kernel #rootkits. Details:
tweet media

Regular sources

9 items
1.00exploit · 05 Sept, 14:12seclists.org

Re: Vulnerability fixes in util-linux-2.42.3

Posted by Salvatore Bonaccorso on Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, Salvatore

1.00general · 04 Sept, 09:18thehackernews.comWild exploit

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerabil…

1.00general · 04 Sept, 08:47thehackernews.comPoC

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artifici…

1.00exploit · 04 Sept, 02:13seclists.org

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

Posted by Ron E on Sep 03 Description O-CMS version 1.0.0 contains an authenticated OS command injection vulnerability in the AI CLI configuration functionality. An auth…

1.00exploit · 04 Sept, 02:13seclists.orgRCE

Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

Posted by Ron E on Sep 03 Description Flextype CMS contains a remote code execution vulnerability in the interaction between the Entries API and Shortcodes::registerShor…

1.00exploit · 04 Sept, 02:13seclists.orgRCE

Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution

Posted by Ron E on Sep 03 Description Flextype CMS v1.0.0-alpha.3 contains a stored code execution vulnerability caused by the interaction between globally processed ent…

1.00exploit · 04 Sept, 02:13seclists.org

Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure

Posted by Ron E on Sep 03 Description Flextype CMS v1.0.0-alpha.3 contains a path traversal vulnerability in the Entries copy functionality. An authenticated remote atta…

1.00exploit · 04 Sept, 02:13seclists.orgRCE

Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server

Posted by Ron E on Sep 03 *Description:* Payara Server contains a vulnerability in its Server-Side Includes (SSI) implementation that allows arbitrary operating system c…

0.93general · 05 Sept, 22:14thehackernews.com

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without lo…