Official intelligence summary

HAIJA INTEL REPORT

Generated 22/07/2026, 09:29. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources9
Tweets / X6
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

6 items
@Sysdig avatar
Sysdig @Sysdig
21 Jul, 16:23 · secondary
0.63
Six months of Sysdig TRT research. One uncomfortable shift. AI isn't just a tool anymore. It's an attacker planning, executing, and adapting in real time. Four trends. All observed in the wild. All capable of compounding into a single campaign. Latest from Crystal Morin and
tweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
21 Jul, 22:31 · core
0.56
Original write-up on the fastjson 1.2.83 gadget-free RCE. Have fun reading, I hope you missed writeups without AI slop. Comment here your opinion. https:// fearsoff.org/research/fastj son-1-2-83-rce …
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
21 Jul, 15:15 · core
0.46
Introducing Tradecraft Academy Our new on-demand training platform brings the practitioner-led education we are known for to learners anywhere, anytime. Get started with BloodHound Basics today. Read more: https:// ghst.ly/4ywKLmM Start learning: https:// ghst.ly/4wBbZqE
tweet mediatweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
21 Jul, 11:57 · core
0.42
SubCat by @duty_1g DNS brute forcing, continuous monitoring, screenshots with a built-in web report, and deep browser-based detection for sharper subdomain intelligence. http:// github.com/duty1g/subcat
@vxunderground avatar
vxunderground @vxunderground
21 Jul, 08:58 · secondary
0.39
vx-underground @vxunderground · Jul 21 Article Reverse engineering malware found in the wild #3 Someone DMd me saying they got hit with malware from Discord. Someone was impersonating Eric Parker and WINUTILS. They also did some domain typosquating, or something. Well, I saw thei
@vxunderground avatar
vxunderground @vxunderground
21 Jul, 07:23 · secondary
0.39
vx-underground @vxunderground · Jul 21 Article Reverse engineering malware found in the wild #2 I got a DM. They said they encountered a website with ClickFix that tried to download and execute a malicious Python script. They didn't provide the website, but they provided the mali

Regular sources

9 items
1.00exploit · 21 Jul, 17:00seclists.orgTradecraft

LPE in snapd and other vulnerabilities

Posted by Eduardo Barretto on Jul 21 Hi everyone, Qualys discovered another Local Privilege Escalation (LPE) in snapd snap-confine, via Capabilities misconfiguration. Qu…

1.00general · 21 Jul, 16:27helpnetsecurity.com

AI agents tricked into recommending malicious GitHub repositories

Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in A…

1.00general · 21 Jul, 10:59thehackernews.comRCEWild exploit

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete c…

1.00general · 21 Jul, 09:34thehackernews.comRCE

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The sam…

1.00exploit · 21 Jul, 07:40seclists.org

New Release: UFONet v2.0 - "R3DST4R!"...

Posted by psy on Jul 20 Hi Community, https://ufonet.03c8.net --------- "UFONet is a free software, P2P and cryptographic -disruptive toolkit- that allows to perform DoS…

0.93general · 21 Jul, 00:23bleepingcomputer.com

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN…

0.90critical · 21 Jul, 14:00cisa.govTradecraft

Siemens IAM Client

View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform…

0.89exploit · 21 Jul, 07:40seclists.org

XSSer v.1.9 - "Bl4ck Swarm!" released

Posted by psy on Jul 20 Hi FD, https://xsser.03c8.net --------- "Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerab…