Official intelligence summary

HAIJA INTEL REPORT

Generated 29/06/2026, 09:20. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources7
Tweets / X8
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

8 items
@_dirkjan avatar
_dirkjan @_dirkjan
26 Jun, 14:00 · core
0.52
Here are the slides from our @WEareTROOPERS presentation - "Modern Adventures in Azure Privilege Escalation" This was a fantastic conference and I'm so glad that we finally got to do this. I have a few more thoughts on it in the thread https:// notpayloads.blob.core.windows.net/s
@SentinelOne avatar
SentinelOne @SentinelOne
27 Jun, 00:11 · secondary
0.48
Law enforcement dismantled malware and scam infrastructure, a North Korean macOS implant disrupted AI analysis tools, and attackers exploited two high-severity vulnerabilities in Cisco edge devices. This is the Good, Bad & Ugly. GOOD - Authorities dismantled the Amadey
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
27 Jun, 11:03 · core
0.40
Great post. If you are at Virus Bulletin, I will be giving a talk aboit this exact topic, how we see threat actors use disposable tooling and what it implies for malware analysts ;) First blog post in a mini series where I look at "disposable tooling". This post shares what I hav
tweet media
@TheDFIRReport avatar
TheDFIRReport @TheDFIRReport
27 Jun, 14:00 · core
0.36
New report out Monday 6/29 by Jake, Dino, Ahmed Farouk, @MittenSec , @angelo_violetti , and @r3nzsec "The threat actor used BumbleBee, AdaptixC2 and RustDesk, in addition to a reverse SSH tunnel to establish connections to their C2 infrastructure."
tweet mediatweet media
@intigriti avatar
intigriti @intigriti
26 Jun, 18:08 · secondary
0.35
Latest Bug Bytes is live! This month's issue is as usual packed with bug bounty tips: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping
tweet mediatweet media
@vxunderground avatar
vxunderground @vxunderground
26 Jun, 07:01 · secondary
0.35
Chat, I'm flabbergasted. I had a few people DM saying this account is spreading malware. They said the GitHub has a .exe which is suspicious. I poked it with a stick. It is, in fact, NOT malware. https:// gist.github.com/vxunderground/ 380cf9e275817732a1f8bd6a120f2e68 … THIS TOOL
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
28 Jun, 18:55 · core
0.28
Just after the UK had the same type of campaign… x.com/polymarket/sta…
tweet media
@_xpn_ avatar
_xpn_ @_xpn_
27 Jun, 13:05 · core
0.28
LLMs can now autonomously generate fully functional Mythic C2 agents from a single prompt. Built, tested, and deployed in under 2 hours. No human in the loop. SpecterOps built a framework called Oracle that takes a prompt, generates the agent code, compiles it, deploys it to a
tweet mediatweet media

Regular sources

7 items
1.00general · 27 Jun, 16:22bleepingcomputer.com

Clean GitHub repo tricks AI coding agents into running malware

An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scann…

1.00exploit · 27 Jun, 16:16seclists.orgRCE

fetchmail's NTLM authentication vulnerable to stack buffer overflow up to release 6.6.6 (FW: The 6.6.7.rc1 release candidate is available (security fix for NTLM protocol, possible…

Posted by Matthias Andree on Jun 27 fetchmail release candidate 6.6.7.rc1 fixes a potential remote code execution (stack smashing) in the NTLM authentication code. It is…

1.00general · 26 Jun, 20:17thehackernews.com

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cob…

1.00general · 26 Jun, 14:31thehackernews.comRCE

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC…

1.00general · 26 Jun, 10:15securityweek.comRCEWild exploit

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerabil…

0.84general · 26 Jun, 13:41helpnetsecurity.com

Critical open-source projects get a new security framework

Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linu…

0.84general · 26 Jun, 10:00securityweek.com

New Enterprise-Ready MCP Specification Brings New Security Challenges

A major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators. The post New Ente…