
HAIJA INTEL REPORT
Tweets / X
6 items








Regular sources
9 itemsRe: Fwd: Node.js security updates for all active release lines, June 2026
Posted by Solar Designer on Jun 19 Thanks. I include the actual content below. This is taken from: https://raw.githubusercontent.com/nodejs/nodejs.org/refs/heads/main/ap…
Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
This week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exp…
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent …
Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware
A cryptocurrency-stealing malware campaign used inflated GitHub activity, software reviews, YouTube tutorials and favorable VirusTotal comments to make malicious trading…
AutoJack: How a single page can RCE the host running your AI agent
AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusin…
Re: Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Posted by Jeremy Stanley on Jun 18 [...] [...] I suppose it depends on the project's practices. For some projects in which I'm involved doing upstream vulnerability coor…
Webinar: How attackers bypass MFA and how defenders can respond
Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This …
OpenBSD mpls_do_error: Remote Kernel Stack Disclosure via MPLS Label Stack Over-read
Posted by shj on Jun 20 ------------------------------------------------------------------------ OpenBSD mpls_do_error: Remote Kernel Stack Disclosure via MPLS Label Sta…
OpenBSD sppp_pap_input: PAP authentication bypass
Posted by shj on Jun 20 ------------------------------------------------------------------------ OpenBSD sppp_pap_input: PAP Authentication Bypass via Zero-Length bcmp -…