
HAIJA INTEL REPORT
Tweets / X
6 items




Regular sources
9 itemsLPE in snapd and other vulnerabilities
Posted by Eduardo Barretto on Jul 21 Hi everyone, Qualys discovered another Local Privilege Escalation (LPE) in snapd snap-confine, via Capabilities misconfiguration. Qu…
AI agents tricked into recommending malicious GitHub repositories
Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in A…
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete c…
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The sam…
New Release: UFONet v2.0 - "R3DST4R!"...
Posted by psy on Jul 20 Hi Community, https://ufonet.03c8.net --------- "UFONet is a free software, P2P and cryptographic -disruptive toolkit- that allows to perform DoS…
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN…
Siemens IAM Client
View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform…
libssh 0.12.1 and 0.11.5 security releases
Posted by Alan Coopersmith on Jul 21 https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ announces:
XSSer v.1.9 - "Bl4ck Swarm!" released
Posted by psy on Jul 20 Hi FD, https://xsser.03c8.net --------- "Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerab…