Official intelligence summary

HAIJA INTEL REPORT

Generated 27/07/2026, 09:44. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources9
Tweets / X6
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

6 items
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
24 Jul, 23:19 · secondary
0.59
Four evasion techniques deliver stealthy device code phishing: blob URLs evade network analyzers, custom CAPTCHA gates block URL scanners, SaaS multi-step flows bypass domain reputation checks, plus source-code evasion. Details at https:// bit.ly/4wZQGPs
tweet mediatweet media
@SentinelOne avatar
SentinelOne @SentinelOne
25 Jul, 00:12 · secondary
0.50
Law enforcement dismantled a massive phishing-as-a-service network, a novel malware hijacked Microsoft 365 calendars for covert communications, and an autonomous AI agent breached Hugging Face. This is the Good, Bad & Ugly. GOOD - German and U.S. authorities dismantled
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
25 Jul, 16:02 · core
0.40
My research landed in this one :D tl;dr sec 338 @OpenAI and Hugging Face, Accelerating EDR Evasion, @Google's Mantis https:// tldrsec.com/p/tldr-sec-338
tweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
24 Jul, 23:14 · core
0.38
We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab. The
tweet mediatweet media
@ShitSecure avatar
ShitSecure @ShitSecure
24 Jul, 05:56 · curator
0.38
Happy to share a technical analysis by @h0j3n on our recent CVE-2026-54121 a.k.a Certighost. glhf Technical analysis: https:// gist.github.com/H0j3n/a5ef2609 b5f2944ac2390a191a534c26 … POC: https:// github.com/aniqfakhrul/CV E-2026-54121 …
tweet mediatweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
24 Jul, 20:46 · secondary
0.35
New #Rhadamanthys #infostealer campaign seen following Global Law Enforcement infrastructure takedown. Attackers impersonated the RingCentral site by using web pages illegally copied from the publicly-available legitimate RingCentral download site. More: https:// bit.ly/3T8zxEV
tweet mediatweet media

Regular sources

9 items
1.00general · 26 Jul, 10:00helpnetsecurity.comRCEWild exploit

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more …

1.00general · 25 Jul, 12:14thehackernews.comRCEPoC

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git…

1.00general · 25 Jul, 12:14thehackernews.comRCE

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmil…

1.00general · 24 Jul, 21:09bleepingcomputer.comTradecraft

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of F…

1.00general · 24 Jul, 09:41thehackernews.com

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest ag…

1.00general · 24 Jul, 08:58thehackernews.comRCE

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains requ…

0.99general · 24 Jul, 13:30thehackernews.com

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing …

0.92general · 24 Jul, 17:12thehackernews.comAttack path

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishin…

0.84general · 24 Jul, 09:00darkreading.com

Europe's Multilingual Reality Exposes AI Security Gaps

The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.