Official intelligence summary

HAIJA INTEL REPORT

Generated 29/09/2026, 10:04. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items7
Regular sources7
Tweets / X0
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

0 items

Regular sources

7 items
1.00general · 28 Sept, 17:49bleepingcomputer.com

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]

1.00general · 28 Sept, 09:21thehackernews.comWild exploit

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabiliti…

0.92exploit · 28 Sept, 19:09seclists.orgTradecraft

CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin

Posted by Jean-Baptiste Onofré on Sep 28 Severity: moderate Affected versions: - Apache Karaf before 4.4.12 Description: Apache Karaf's shell/SSH command security is enf…

0.92exploit · 28 Sept, 18:02seclists.orgRCETradecraft

CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create

Posted by Jean-Baptiste Onofré on Sep 28 Severity: moderate Affected versions: - Apache Karaf before 4.4.12 Description: The jdbc shell command scope shipped no org.apac…

0.91general · 28 Sept, 17:33darkreading.com

JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack

The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.

0.89exploit · 28 Sept, 13:56seclists.org

crontab(1) silently truncates file path arguments >=100 chars

Posted by Vincent Lefevre on Sep 28 A "minor" bug in cron was reported in the Debian BTS: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144850 "cron: crontab(1) sil…