Official intelligence summary

HAIJA INTEL REPORT

Generated 29/07/2026, 09:49. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources7
Tweets / X8
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

8 items
@harmj0y avatar
harmj0y @harmj0y
28 Jul, 14:18 · core
0.60
ESC1 is alive again. Low priv user to Domain Admin on a fully patched AD CS. Enforcement set to 2. The issued cert came back with NO szOID_NTDS_CA_SECURITY_EXT at all, over the CMC addExtensions path. MSRC: "Not a Vulnerability." Original research by @harmj0y and @tifkin_ .
tweet mediatweet media
RA
Rapid7 @Rapid7
28 Jul, 21:36 · secondary
0.59
On 7/22/26, #CheckPoint published a security advisory for CVE-2026-16232 - an authentication bypass vuln in SmartConsole, which admins use to manage Check Point policy & configuration. For our technical analysis, proof …
@SpecterOps avatar
SpecterOps @SpecterOps
28 Jul, 16:02 · core
0.54
Your attack surface doesn't stop at AD. BloodHound Enterprise now supports AWS & Microsoft Entra Agent ID. We're also introducing BloodHound Hunter to bring attack path intel into AI workflows. Learn more https:// ghst.ly/4fZQN7W
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
28 Jul, 02:51 · core
0.46
Want to get more from BloodHound? Our BloodHound Basics course teaches you how to collect data, analyze attack paths, write Cypher queries, work with OpenGraph, and more through hands-on labs. Available now in Tradecraft Academy: https:// ghst.ly/4wBbZqE
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
28 Jul, 21:24 · core
0.42
An MCP server isn't just a wrapper around your REST API. AI agents explore before they act, so MCP tools should be designed around intent, not implementation. Kaleb Pomeroy explains why that distinction matters for security workflows. https:// ghst.ly/4x80M0X
tweet media
@brutelogic avatar
brutelogic @brutelogic
28 Jul, 16:29 · secondary
0.38
Know every way to break a JWT. Every technique, every payload, tested and ready. Algorithm confusion, header field injection, claim manipulation, format attacks - including original research not documented in any public resource. https:// brutelogic.net/ebooks/broken- token/jwt …
tweet mediatweet media
@BishopFox avatar
BishopFox @BishopFox
28 Jul, 21:39 · secondary
0.35
A critical CVE... A predictable SSO ticket... An account takeover! So why isn't this being mass exploited? Our latest research on CVE-2026-11374 breaks down the attack path, why exploitability is limited, and what defenders should do next.
tweet mediatweet media
@pdiscoveryio avatar
pdiscoveryio @pdiscoveryio
28 Jul, 19:00 · secondary
0.35
Finding a potential XSS is only the first step. Neo automatically : -> opens a real browser -> executes the payload -> confirms JavaScript execution -> captures the alert screenshot as evidence -> Introducing Neo Browser Computer Use -- an autonomous PoC collector. Finding XSS
tweet media

Regular sources

7 items
1.00general · 28 Jul, 20:08bleepingcomputer.comRCEWild exploit

vBulletin fixes critical pre-auth RCE flaw with public exploit

A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]

1.00exploit · 28 Jul, 07:55seclists.orgTradecraft

[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM

Posted by advisories on Jul 27 ---------------------------------------------------------------------------- NotCVE Advisory - NotCVE-2026-0010 --------------------------…

1.00general · 28 Jul, 06:43thehackernews.comWild exploit

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability,…

1.00general · 28 Jul, 01:49bleepingcomputer.comRCE

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.…

0.92general · 28 Jul, 06:30helpnetsecurity.comAttack path

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts

Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are …

0.89exploit · 28 Jul, 07:48seclists.org

Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD

Posted by Sam James on Jul 27 Reid Sutherland writes: Paolo has been a maintainer for a long time and in FOSS even longer than that. Big refactoring can introduce bugs b…

0.74critical · 28 Jul, 14:00cisa.govRCE

Siemens Desigo CC

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow…