Official intelligence summary

HAIJA INTEL REPORT

Generated 21/07/2026, 09:28. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources7
Tweets / X8
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

8 items
@_RastaMouse avatar
_RastaMouse @_RastaMouse
20 Jul, 19:13 · core
0.68
I explored the windows global device identifier (GDID) and wrote a poc, including a BoF to extract it. But the main question is: Can we patch another user's GDID ? Repo (coff BoF, Rust/C PoC) :- https:// github.com/5mukx/GDID-Ext ractor … Read the full Research here:- https:// ze
tweet mediatweet media
RA
Rapid7 @Rapid7
20 Jul, 14:04 · secondary
0.67
On 7/17/26, a #GitHub Security Advisory was published for CVE-2026-63030 - a critical unauth. RCE vuln. in #WordPress Core. No valid account or user interaction is required, and successful exploitation may result in ful…
@nahamsec avatar
nahamsec @nahamsec
20 Jul, 17:03 · core
0.62
NEW COURSE & EARLY ACCESS SALE: Hacking AI Apps & Agents Force a chatbot to leak internal secrets. Poison an agent's memory so your malicious instructions execute long after you're gone. Chain an indirect prompt injection into automated data exfiltration and remote code
tweet mediatweet media
@_xpn_ avatar
_xpn_ @_xpn_
20 Jul, 20:37 · core
0.56
This so if American companies are forced to restrict cyber use cases, won't exploit researchers, hackers, threat actors, all just use chinese models? how is that better?
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
20 Jul, 17:35 · secondary
0.48
Our joint research with Siemens details a critical exploit chain of three zero-day vulnerabilities in Ruggedcom ROX II OT switches. This chain allows attackers to achieve persistent root access on critical industrial network devices: https:// bit.ly/4gJZxAc
tweet mediatweet media
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
20 Jul, 10:10 · core
0.46
Seems that wp2shell PoCs are now floating around the internet, so we've published our blog post including our research methodology for finding the bug as well as a deep dive into the chain itself -
tweet media
@SpecterOps avatar
SpecterOps @SpecterOps
20 Jul, 19:55 · core
0.40
The hunt returns July 22. Complete the #BloodHoundUnleashed Attack Path Championship before #BHUSA, then visit Kennel Club during the event for bonus codes that can boost your leaderboard score. More soon.
tweet mediatweet media
@Rapid7 avatar
Rapid7 @Rapid7
20 Jul, 15:34 · secondary
0.34
An MDR alert recently pointed Rapid7 to an exposed server acting as a fully operational malware delivery lab. The exposed infrastructure showed how the operator tested delivery paths, packaged lures, staged payloads & more - all with the help of genAI: https:// r-7.co/3RnpqLC
tweet mediatweet media

Regular sources

7 items
1.00general · 20 Jul, 20:30darkreading.comAttack path

Attackers Combo Up Evasion Tactics for BEC Phishing

"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private …

1.00general · 20 Jul, 20:23thehackernews.com

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Con…

1.00general · 20 Jul, 19:29thehackernews.comAttack path

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution …

1.00general · 20 Jul, 16:32helpnetsecurity.comRCEWild exploit

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. …

1.00general · 20 Jul, 15:32thehackernews.comRCE

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths …

0.93general · 20 Jul, 16:33thehackernews.com

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen fil…

0.84general · 20 Jul, 12:25securityweek.com

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-…