Official intelligence summary

HAIJA INTEL REPORT

Generated 05/08/2026, 09:36. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources9
Tweets / X6
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

6 items
@_xpn_ avatar
_xpn_ @_xpn_
04 Aug, 23:44 · core
0.62
That is so cool!!!! In one example of many, the AI agent set up multiple GitHub accounts to try and SE a PR to be accepted. Something really unnerving about agents now attacking humans without direction Well written disclosure by AISI! http:// aisi.gov.uk/blog/incident- report-un
tweet mediatweet media
@brutelogic avatar
brutelogic @brutelogic
04 Aug, 16:29 · secondary
0.49
SSRF Network Polyglots 1. Backend (curl, Python, PHP): http://trusted.com@0177.0.0.1#@trusted.com 2. Browser-triggered (redirects, img/iframe, client fetch): http:/\a@trusted.com@0177%EF%BD%A10%EF%BD%A10%EF%BD%A11#@trusted.com Browsers normalize what backend clients reject. SSRF
tweet media
@Sysdig avatar
Sysdig @Sysdig
04 Aug, 16:00 · secondary
0.39
Today we're launching Sysdig Secure AI. In 2018, attackers took over two years to exploit a vulnerability. Today it's hours. Sometimes even minutes. Sysdig Secure AI puts an expert AI security team to work for you, investigating, remediating, and responding at the speed
tweet media
@TheDFIRReport avatar
TheDFIRReport @TheDFIRReport
04 Aug, 13:10 · core
0.34
EtherRAT brought blockchain-backed C2 into this intrusion. A malicious MSI masquerading as Sysinternals RAMMap deployed EtherRAT, which used EtherHiding to retrieve Ethereum-hosted C2 config updates before pivoting to TryCloudflare infrastructure. Full report:
tweet mediatweet media
@vxunderground avatar
vxunderground @vxunderground
04 Aug, 21:27 · secondary
0.32
Hi More malware has been uploaded to VXUG. It's like, 150,000 malwares, or something. I also uploaded more malware analysis papers. Show it to your parents, they'll be proud of you.
@brutelogic avatar
brutelogic @brutelogic
04 Aug, 16:27 · secondary
0.32
SSRF pays well and the attack surface keeps expanding. Most hunters test randomly and miss what matters. Discovery, parser exploitation, blind confirmation chains, cloud metadata attacks. The path to consistent five-figure bounties. http:// brutelogic.net/ebooks/ssrf-ma stery-ser
tweet mediatweet media

Regular sources

9 items
1.00general · 04 Aug, 19:27thehackernews.comAttack path

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growi…

1.00general · 04 Aug, 16:10helpnetsecurity.com

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Net…

1.00general · 04 Aug, 15:54securityweek.comWild exploit

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitat…

1.00critical · 04 Aug, 14:00cisa.govWild exploit

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code …

1.00general · 04 Aug, 13:16thehackernews.com

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a tria…

1.00general · 04 Aug, 09:00thehackernews.comWild exploit

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerab…

1.00general · 04 Aug, 06:00snyk.ioResearch

Evo Continuous Offensive Security Is Here Pentesting Grade Coverage For The 350 Days A Year You Aren't Testing

Snyk Evo Continuous Offensive Security brings autonomous, AI-powered pentesting to the 350 days between traditional tests, uncovering exploitable flaws attackers can fin…

0.99general · 04 Aug, 15:15helpnetsecurity.com

Snyk unveils continuous AI pentesting and agent red teaming

Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-pow…

0.93general · 04 Aug, 14:50unit42.paloaltonetworks.com

Almost Half of Malware Samples Communicate Direct to IP

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of …