Official intelligence summary

HAIJA INTEL REPORT

Generated 03/08/2026, 09:42. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources9
Tweets / X6
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

6 items
@outflanknl avatar
outflanknl @outflanknl
31 Jul, 18:00 · core
0.68
Join red team operator Max Grim as he presents “Modern C2 Teamserver Design with AI-driven Operator Guidance” on Wednesday, August 5 at 11:30 a.m. Our full schedule of red team ops tradecraft presentations during @BlackHatEvents USA 2026 is posted here: https:// cobaltstrike.com/
tweet mediatweet media
@intigriti avatar
intigriti @intigriti
31 Jul, 18:08 · secondary
0.50
Latest Bug Bytes is live! This month's issue is as usual packed with bug bounty tips: Intigriti turns 10! RCE in GitHub and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
31 Jul, 16:25 · core
0.50
If you saw this on your computer screen, would you suspect it to be a malware-initiated passkey phishing attack? I will be presenting various deception techniques at #BHUSA next week. https:// blackhat.com/us-26/briefing s/schedule/?#pass-the-passkey-family-of-attacks-51821 …
tweet mediatweet media
@mrgretzky avatar
mrgretzky @mrgretzky
01 Aug, 11:15 · core
0.48
Compiled #V8 bytecode is still a niche #malware format, but it highlights a broader analysis problem: what happens when a payload falls between established toolchains? At #BlackHat2026, I’ll walk through the #JSCeal case study and the static deobfuscation toolkit I built to
tweet mediatweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
31 Jul, 16:56 · secondary
0.46
We've discovered malicious #npm & #PyPI packages on public registries, 65% previously unknown. Attacks include .env credential theft, crypto wallet stealing, RCE droppers, & #MCP server backdoors targeting AI developers. Details on the extracted malware at
tweet media
@harmj0y avatar
harmj0y @harmj0y
31 Jul, 14:26 · core
0.42
Super interesting release! Malleable profiles and randomized API hashes per-build Metasploit 6.5 is out just in time for Hack Summer Camp. This release comes with Malleable C2 support for Meterpreter, more relaying improvements and an integrated MCP server. Check out all the deta
tweet media

Regular sources

9 items
1.00general · 02 Aug, 10:00helpnetsecurity.comPoCAttack path

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the s…

1.00general · 01 Aug, 13:15securityweek.comRCE

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critic…

1.00general · 31 Jul, 18:39thehackernews.comAttack path

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka…

1.00general · 31 Jul, 16:01bleepingcomputer.com

ESET tracks rise in malicious AI skills and adaptable malware

Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious…

1.00general · 31 Jul, 13:24thehackernews.comAttack path

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale …

1.00general · 31 Jul, 02:00intigriti.comRCEResearch

Intigriti Bug Bytes #238 - July 2026 🚀

Hello hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server …

0.96exploit · 02 Aug, 23:246 mentionsseclists.org

Re: Some Changes to GNOME Security Tracking

Posted by Peter Gutmann on Jul 30 Alan Coopersmith writes: So you've got a bunch of projects where people are clamoring for them to reject anything that might have been … | Posted by Demi Marie Obenour on Aug 02 General comment on security fixes in open source projects: I think the motivation for projects like Akrites is simple. Companies n… | Posted by Solar Designer on Aug 02 Hi, [...] This thread and the "33 Vulnerabilities in cJSON" one are becoming increasingly difficult to moderate. While I understand th…

0.89exploit · 02 Aug, 04:21seclists.org

Lean 4 kernel soundness bug: forging proofs via nested inductive projections (0 = 1 demonstrated)

Posted by Jonathan Brossard on Aug 01 Dear list, I hope this email finds you well. I'd like to bring attention to a soundness vulnerability in the Lean 4 theorem prover …

0.89exploit · 01 Aug, 16:182 mentionsseclists.org

Re: 33 Vulnerabilities in cJSON

Posted by Collin Funk on Aug 01 Peter Gutmann writes: Note that I am not a maintainer of cJSON, and have never interacted with them. My understanding is that the maintai… | Posted by Peter Gutmann on Jul 31 Collin Funk writes: I assume you're new to this process so I'll explain: When someone submits bug reports to your project that help fix…