Official intelligence summary

HAIJA INTEL REPORT

Generated 25/06/2026, 09:20. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources5
Tweets / X10
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

10 items
MA
Mandiant @Mandiant
24 Jun, 18:15 · secondary
0.55
NEW THREAT INTEL: Zero-day exploitation (CVE-2026-20245) of Cisco Catalyst SD-WAN Manager. A threat actor gained root access via malicious CSV upload, and used anti-forensic techniques for evasion. Get the details, IOCs…
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
24 Jun, 18:52 · secondary
0.49
We detected a Browser-in-the-Browser phishing kit for malware delivery rather than credential theft. It uses a draggable pop-up with a spoofed URL to serve a fake "software out of date" warning. It sends malware that it instructs users to run. Details at https:// bit.ly/3SFpmHp
tweet mediatweet media
@SentinelOne avatar
SentinelOne @SentinelOne
24 Jun, 00:58 · secondary
0.48
At the time of writing: 0/61 detections on VirusTotal. The rest of the tradecraft is hardened: - C2 runs over Telegram, AES-GCM encrypted, certificate-pinned TLS - The bot token self-redacts, leaving only a placeholder in logs and crash artifacts - Python stealer harvests
@Synack avatar
Synack @Synack
24 Jun, 18:54 · secondary
0.39
SRT researcher @ozgur_bbh walks through two real-world 2FA bypasses: https:// synack.com/exploits-expla ined/how-attackers-bypass-2fa-with-response-tampering/?utm_campaign=5710519-PTAAS-FY26&utm_source=organic-social&utm_medium=organic-social&utm_audience=all&utm_content=exploits
tweet mediatweet media
@CrowdStrike avatar
CrowdStrike @CrowdStrike
24 Jun, 20:58 · secondary
0.32
Today’s threat actors are evolving. They’re accelerating their tradecraft with AI, evading detection, and challenging traditional security defenses. Get to know their methods and motivations in the CrowdStrike 2026 Global Threat Report: https:// crwdstr.ke/6015BDgU6P
tweet media
@_xpn_ avatar
_xpn_ @_xpn_
24 Jun, 19:50 · core
0.32
First blog post in a mini series where I look at "disposable tooling". This post shares what I have found to be useful when 1-shot'ing LLM generated Stage-0 agents for Mythic.
tweet media
@RedCanary avatar
RedCanary @RedCanary
24 Jun, 17:53 · secondary
0.32
Just wanted to give kudos to how the Zscaler @Threatlabz team have been crushing it recently Two awesome blogs caught my eye on novel malware families linked to ransomware gangs: 1. MLTBackdoor https:// zscaler.com/blogs/security -research/technical-analysis-mltbackdoor … 2. Edge
@mrgretzky avatar
mrgretzky @mrgretzky
24 Jun, 02:57 · core
0.32
Will a powerful enough model wipe out harnessing gains? My research suggests: not yet! And cost savings matter more and more as capabilities democratize. See you down under We are excited to announce our first speaker for http:// Unprompted.au: Valentina Palmiotti (@chompie1337),
tweet media
@Synack avatar
Synack @Synack
24 Jun, 22:16 · secondary
0.29
Learn how @Accenture eliminated entire vulnerability classes w/ Synack: https:// go.synack.com/continuous-off ensive-security-accenture-case-study?utm_campaign=5710519-PTAAS-FY26&utm_source=organic-social&utm_medium=organic-social&utm_audience=general&utm_content=case-study-accen
tweet mediatweet media
@intigriti avatar
intigriti @intigriti
24 Jun, 11:08 · secondary
0.28
Intigriti's June Challenge is over! 43 hackers found the correct solution 10 hackers wrote a cool writeup Check out the winners below and drop your write-up in the comments! It's CHALLENGE O'CLOCK! Capture the flag before Monday the 22nd of June Win €400 in SWAG prizes We'll rele
tweet media

Regular sources

5 items
1.00general · 24 Jun, 19:19thehackernews.comWild exploit

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series …

1.00exploit · 24 Jun, 18:46seclists.org

Multiple vulnerabilities in Jenkins plugins

Posted by Kevin Guerroudj on Jun 24 Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their softw…

1.00general · 24 Jun, 14:48thehackernews.com

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "cr…

0.89exploit · 24 Jun, 18:39seclists.org

[SECURITY ADVISORIES] for curl 8.21.0

Posted by Daniel Stenberg on Jun 24 Hello friends, In association with the curl release 8.21.0 that we announced just minutes ago, we publish no less than eighteen new c…

0.84general · 24 Jun, 14:00securityweek.com

Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed

Context is the central plank of AI in general, and agentic AI in particular. If an AI system doesn’t have the correct context, it cannot make the correct decisions. The …