Official intelligence summary

HAIJA INTEL REPORT

Generated 23/09/2026, 10:21. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources15
Tweets / X0
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

0 items

Regular sources

15 items
1.00exploit · 22 Sept, 20:34seclists.org

Code Security Review tool

Posted by E. Kellinis on Sep 22 Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro is a macOS source…

1.00general · 22 Sept, 19:32darkreading.comAttack path

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.

1.00exploit · 22 Sept, 18:29seclists.org

rsyslog imdtls permitted-peer authorization bypass

Posted by Rainer Gerhards on Sep 22 Hello, The optional rsyslog imdtls input module did not enforce tls.permittedpeer after a successful CA-authenticated DTLS handshake …

1.00general · 22 Sept, 17:00microsoft.comAttack pathResearch

Unmasking EvilTokens: Getting to the root of device code phishing

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft.…

1.00general · 22 Sept, 14:30thehackernews.comTradecraft

AI Agents Are Rewriting the Rules of Lateral Movement

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous syste…

1.00general · 22 Sept, 07:31thehackernews.comWild exploit

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploite…

0.91general · 22 Sept, 19:03thehackernews.comAttack path

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack ch…

0.89exploit · 22 Sept, 20:32seclists.org

CFP No cON Name 2k26 - Palma, Mallorca - Spain

Posted by Jose Nicolas Castellano on Sep 22 No cON Name 2026 - Palma, Mallorca - Balearic Islands https://www.noconname.org/call-for-papers/ Exact place not disclosed un…

0.89exploit · 22 Sept, 20:31seclists.orgResearch

[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8)

Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in TigerGraph Community Edition 4.2.4. Type: Default …

0.89exploit · 22 Sept, 20:31seclists.orgResearch

[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8)

Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in Teltonika RutOS 00.07.06.21. Type: Authenticated i…