HAIJA INTEL REPORT
Tweets / X
10 items












Regular sources
5 itemsUser prompt injection (CSRF) of the llama-server's Web UI (llama.cpp)
Posted by Gabriel Corona on Jul 18 Hi, The Web UI of llama-server accepts a query parameter (?q=...) as an initial user message in a new conversation and auto-submits th…
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open…
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators p…
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
Posted by Alan Coopersmith on Jul 17 https://www.zerodayinitiative.com/advisories/ZDI-26-444/ advises:
OpenSSL "HollowByte" DoS via attacker-controlled memory allocation size in glibc
Posted by Jan Schaumann on Jul 18 Hi, https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/ OpenSSL fixed it here:...