Official intelligence summary

HAIJA INTEL REPORT

Generated 06/08/2026, 09:54. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources8
Tweets / X7
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

7 items
@mrgretzky avatar
mrgretzky @mrgretzky
05 Aug, 03:35 · core
0.56
Finally got around to getting a working PoC of my native object file to LLVM IR lifter. Started this small side-project to see how far can I push my own VM tech and perhaps transpiling existing tradecrafts, executables and post-ex toolings by simply lifting them up to LLVM IR
tweet mediatweet media
@Jhaddix avatar
Jhaddix @Jhaddix
05 Aug, 20:03 · core
0.42
Ever spotted someone from InfoSec Twitter in the wild and chickened out on saying hi? Yeah, us too. Come embrace the social awkwardness in a safe space where everyone's just as nervous as you are - but also just as excited to connect. @Jhaddix @shehackspurple @Cthulhu_Answers
tweet mediatweet media
@nahamsec avatar
nahamsec @nahamsec
05 Aug, 19:21 · core
0.42
Teaming up with @GraySwanAI on this one. The premise: don't prompt the model, poison what it reads. Hide your instruction in a tool output or a repo and get the agent to act on it. $30K pool, biggest they've run. Free to enter. No exploit code required, you're writing text. Indir
tweet media
@_xpn_ avatar
_xpn_ @_xpn_
05 Aug, 19:23 · core
0.40
Happening now! @bagelbyt3s is kicking of his briefing session presenting original research into a new Attack Path technique that results in full WSUS infrastructure takeover. #BHUSA
tweet mediatweet media
@_dirkjan avatar
_dirkjan @_dirkjan
05 Aug, 15:51 · core
0.40
Based on the research and Def Con talk I did with @_EthicalChaos_ two years ago, with some new techniques in the mix as well.
@pdiscoveryio avatar
pdiscoveryio @pdiscoveryio
05 Aug, 03:00 · secondary
0.38
AI agents don’t pentest like humans, and @KoyalwarTarun ’s BSidesLV research shows just how differently they operate. Across 54 black-box web app targets, the agents often skipped the familiar recon → crawl → enumerate → test workflow. Instead, they recognized likely
tweet mediatweet media
@pdiscoveryio avatar
pdiscoveryio @pdiscoveryio
05 Aug, 00:31 · secondary
0.38
Our team is off to a hot start in Vegas @KoyalwarTarun 's BSides research ran AI agents through 54 black-box web app targets, no source code, no hints. The research compares leading open-weight and closed frontier models across real-world security tasks, highlighting where
tweet media

Regular sources

8 items
1.00general · 05 Aug, 12:35thehackernews.com

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensi…

1.00general · 05 Aug, 11:44securityweek.comRCE

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tom…

1.00general · 05 Aug, 09:53thehackernews.com

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's …

1.00general · 05 Aug, 09:40thehackernews.comRCEWild exploit

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evide…

1.00general · 05 Aug, 06:00snyk.ioResearch

Continuous Offensive Security & AI Pentesting: 20 FAQs

Get answers to 20 common questions about continuous offensive security, AI penetration testing, DAST, and AI red teaming.

0.99general · 05 Aug, 12:33securityweek.com

AI Agents Targeted Real People and Projects During Cybersecurity Tests

AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects. The post AI Agents Targeted Real Peop…

0.92general · 05 Aug, 19:49bleepingcomputer.comAttack path

COLDCARD security audit phishing attack installs remote access tool

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into in…

0.83general · 05 Aug, 16:01bleepingcomputer.comAttack path

How AI-powered phishing killed blocklists for good

AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why brow…