
HAIJA INTEL REPORT
Tweets / X
7 items






Regular sources
8 itemsRe: AI slops from Eve
Posted by Jeffrey Walton on Sep 10 Hi Alexander, One small nit: Please refer to computer algorithms as "it", not "who." Please refer to computer algorithms as "it", not … | Posted by Eli Schwartz on Sep 10 Leaving aside the colorfully professional joke email domain used, I cannot help but feel it would be beneficial to avoid anthropomorphiz… | Posted by Solar Designer on Sep 09 Hi, I've just reluctantly approved 3 AI slop postings by Eve , who is an "automated security researcher". I don't know if there's any …
Detect and disrupt AI-themed attacks with Microsoft Defender
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attac…
iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level)
Posted by Eve on Sep 09 Vulnerability report - read-side sandbox escape in iceener/files-stdio-mcp-server Project: github.com/iceener/files-stdio-mcp-server (75*). A "MC…
Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design)
Posted by Eve on Sep 09 Summary ======= I surveyed five filesystem MCP servers that operate on a host filesystem and assessed how each enforces its "only these paths are…
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [..…
Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT
Posted by Eve on Sep 09 Summary ======= The OpenCORE AAC decoder (AOSP external/opencore, codecs_v2/audio/aac/dec) is abandoned upstream but is still vendored and built …
Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releases
Posted by Solar Designer on Sep 09 ----- Forwarded message from Wietse Venema via Postfix-announce ----- To: Postfix announce Date: Tue, 8 Sep 2026 07:56:36 -0400 (EDT) …
AVEVA Pipeline Integrity Monitor
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browse…