
HAIJA INTEL REPORT
Tweets / X
6 items




Regular sources
9 itemsRe: SEC Consult SA-20260427-0 :: Missing TLS Certificate Validation leading to RCE in DeskTime Time Tracking App
Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Apr 29 *Update 2026-04-28:* The vendor contacted us and now provides a patched version v1.3.674 which can b…
How AI can streamline your security testing
Atomic Red Team’s new MCP server helps you test more, faster as you validate your detection coverage against MITRE ATT&CK techniques
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has …
Re: Coordinated Disclosure in the LLM Age
Posted by Peter Gutmann on Apr 28 Jacob Bachmeyer writes: Not sure if this makes it better or worse, but I've found that Claude/Opus at least gives different answers for… | Posted by Jacob Bachmeyer on Apr 28 The biggest risk is parallel discovery. If an LLM can find a bug for a whitehat, it can do the same for a blackhat. You are correct h…
Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing - traceroute 2.1.2
Posted by Alan Coopersmith on Apr 28 No, you cc'ed oss-security, a public mailing list with public archives: https://www.openwall.com/lists/oss-security/2026/04/28/20 so… | Posted by Jacob Bachmeyer on Apr 28 Oops. The oss-security mailing list is public. If you want to do coordinated disclosure, you might want to avoid sending the initial … | Posted by Solar Designer on Apr 28 Thank you, Dmitry! FWIW, I've just checked that traceroute-2.1.1-1.el9.src.rpm also contains the "n -= hlen;" line where Mohamed propo…
APPLE-SA-04-22-2026-2 iOS 18.7.8 and iPadOS 18.7.8
Posted by Apple Product Security via Fulldisclosure on Apr 29 APPLE-SA-04-22-2026-2 iOS 18.7.8 and iPadOS 18.7.8 https://support.apple.com/en-us/127003. https://support.…
APPLE-SA-04-22-2026-1 iOS 26.4.2 and iPadOS 26.4.2
Posted by Apple Product Security via Fulldisclosure on Apr 29 APPLE-SA-04-22-2026-1 iOS 26.4.2 and iPadOS 26.4.2 https://support.apple.com/en-us/127002. https://support.…
Research: When Trusted Tools Become Attack Primitives
Posted by Nir Yehoshua on Apr 29 Hi Full Disclosure list, I published a technical research article titled: When Trusted Tools Become Attack Primitives The article examin…
[KIS-2026-08] SocialEngine <= 7.8.0 (get-memberall) SQL Injection Vulnerability
Posted by Egidio Romano on Apr 29 ----------------------------------------------------------------- https://socialengine.com [-] Affected Versions: Versions 7.8.0, 7.7.0…