Official intelligence summary

HAIJA INTEL REPORT

Generated 23/06/2026, 09:28. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources3
Tweets / X12
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

12 items
@Sysdig avatar
Sysdig @Sysdig
22 Jun, 23:57 · secondary
0.59
An operator RCE'd a Langflow box, swept env vars, and stole Azure service principal creds, then LLMjacked an Azure AI Foundry endpoint serving Anthropic models. AWS is easy to catch: everyone has CloudTrail. Azure is tough: few stream Entra sign-ins, so a stolen SP trips
@mrgretzky avatar
mrgretzky @mrgretzky
22 Jun, 14:05 · core
0.42
The @x33fcon conference was once again a complete success! I wanted to share the slides and demo videos from the "Downgrading FIDO MFA With AI Slop" talk I gave on the second day (the next day after the pirate ship party... ugh). Slides: https:// github.com/kgretzky/talks /tree/m
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
22 Jun, 21:20 · core
0.40
We're excited to partner with @OpenAI through the Daybreak Cyber Partner Program to help defenders solve one of cybersecurity's toughest challenges: attack path triage. The challenge isn't finding risk. It's knowing which attack paths matter most.
tweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
22 Jun, 18:18 · secondary
0.39
FortiBleed is a large-scale password spraying and credential theft campaign targeting Fortinet, Sophos and MSSQL devices. Threat actors are using a curated password list developed through previous breaches and vulnerability exploits. We detail mitigations: https:// bit.ly/4eDxSxY
tweet mediatweet media
@nahamsec avatar
nahamsec @nahamsec
22 Jun, 21:11 · core
0.32
Shout out to @Ph1R3574R73r for showing me some of his research!
@_dirkjan avatar
_dirkjan @_dirkjan
22 Jun, 17:37 · core
0.32
Not purely original research, but a nice extension on the CA project @fabian_bader and I started last year.
@ShitSecure avatar
ShitSecure @ShitSecure
22 Jun, 17:35 · curator
0.27
I just wrote a new blog on bypassing CA policies in Entra ID that have a resource exclusion, and why you probably want to enable baseline enforcement if you have such policies. Enjoy!
@vxunderground avatar
vxunderground @vxunderground
22 Jun, 21:02 · secondary
0.24
Hello 1. If you're reading this, that means you live inside my computer. Please leave my computer. You are stinking the place up. 2. I am syncing 150,000+ malwares to the internet. Please download the malware. 3. I now possess 14TB (7z ultra compressed) of malware
tweet mediatweet media
@pdiscoveryio avatar
pdiscoveryio @pdiscoveryio
22 Jun, 17:31 · secondary
0.24
Is there an existential threat to ProjectDiscovery? We aren’t buying into the AI "psychosis" or "apocalypse" narrative. Instead, our focus remains on ensuring we consistently deliver high value to the security community. Staying ahead means moving faster.
tweet media
@Bugcrowd avatar
Bugcrowd @Bugcrowd
22 Jun, 17:45 · secondary
0.22
12 out of 15 top-tier hackers ignore standard security methodologies. New research into hacker cognition reveals that elite researchers don’t follow rigid checklists when testing a target. Instead, they rely on fast, intuitive pattern recognition built from years of
tweet media
@Sysdig avatar
Sysdig @Sysdig
22 Jun, 16:41 · secondary
0.22
LLMjacking has evolved. A threat actor used an exposed Ollama server as the brain for an autonomous, multi-stage offensive hacking tool. Not reselling access. Building with it. Sysdig TRT caught the tool while it was still in development. Full research:
tweet mediatweet media
@brutelogic avatar
brutelogic @brutelogic
22 Jun, 16:22 · secondary
0.22
Research or Content? 3 Rules Most security research out there isn't research. It's content. There's a difference, and it comes down to three things. 1. Correct and Defensible Every claim, every payload, every technique must hold under scrutiny. Not "it worked once in my lab."
tweet mediatweet media

Regular sources

3 items
1.00general · 22 Jun, 07:30helpnetsecurity.com

Agent Beacon: Open-source telemetry layer for AI agents

AI coding agents such as Claude Code, Codex CLI, Cursor, and Claude Cowork run on developer laptops, CI jobs, cloud environments, where they edit files, run commands, an…

0.97exploit · 22 Jun, 20:172 mentionsseclists.org

Re: Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)

Posted by Jeremy Stanley on Jun 22 [...] It's both... Yes advance notification in the case of embargoed vulnerabilities is going to the linux-distros mailing list as wel… | Posted by Sylvain Beucler on Jun 22 Hello Jeremy, Interesting. This seems like an embargo-like workflow, usually for high/critical CVEs, which I believe won't involve se…

0.93general · 22 Jun, 12:30securityweek.com

What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks

Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage. The post What the Latest ShinyHun…