Official intelligence summary

HAIJA INTEL REPORT

Generated 07/10/2026, 10:38. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources15
Tweets / X0
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

0 items

Regular sources

15 items
1.00general · 06 Oct, 19:56darkreading.com

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

1.00exploit · 06 Oct, 19:44seclists.orgResearch

[0day-rubbish] RCDevs WebADM 2.4.14 authenticated log viewer sid command injection to webadm uid 999 code execution (7.2)

Posted by disclosure via Fulldisclosure on Oct 06 0day Rubbish Research Team is publicly disclosing a vulnerability in RCDevs WebADM 2.4.14, Freeware Edition, the closed…

1.00exploit · 06 Oct, 19:44seclists.orgResearch

[0day-rubbish] Advantech WebAccess Node 9.2.3 unauthenticated CrystalRpt.aspx file upload and path traversal to code execution in w3wp.exe (9.8)

Posted by disclosure via Fulldisclosure on Oct 06 0day Rubbish Research Team is publicly disclosing a vulnerability in Advantech WebAccess Node 9.2.3, the closed-source …

1.00critical · 06 Oct, 14:00cisa.govRCE

Hitachi Energy SOI

View CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. Thes…

1.00general · 06 Oct, 12:00unit42.paloaltonetworks.comResearch

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder …

0.97critical · 06 Oct, 14:00cisa.govRCE

Savannah lwIP SMTP client

View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The f…

0.89exploit · 06 Oct, 19:44seclists.orgResearch

[0day-rubbish] StreamSets Transformer 3.17.0 auth-mode none fallback and un-sandboxed ScalaDTransform execution to container root (8.1 primary)

Posted by disclosure via Fulldisclosure on Oct 06 0day Rubbish Research Team is publicly disclosing a vulnerability in StreamSets Transformer, the Spark-engine data-pipe…

0.89exploit · 06 Oct, 19:44seclists.orgResearch

[0day-rubbish] Maian Cart 3.8 addBanners unrestricted banner upload to PHP webshell and administrator command execution (7.2 primary, PR:H)

Posted by disclosure via Fulldisclosure on Oct 06 0day Rubbish Research Team is publicly disclosing a vulnerability in Maian Cart 3.8, the self-hosted PHP shopping-cart …

0.89exploit · 06 Oct, 19:44seclists.orgResearch

[0day-rubbish] IPConfigure Orchid VMS 26.3.0 authenticated DNF repository GPG-key property command injection to root (7.2)

Posted by disclosure via Fulldisclosure on Oct 06 0day Rubbish Research Team is publicly disclosing a vulnerability in IPConfigure Orchid VMS, installed as Orchid Record…

0.89exploit · 06 Oct, 19:44seclists.orgResearch

[0day-rubbish] Circutor LineEds 24.11.14-r0 unauthenticated pwrstudio events.xml shellExecute command injection (9.8)

Posted by disclosure via Fulldisclosure on Oct 06 0day Rubbish Research Team is publicly disclosing a vulnerability in the pwrstudio daemon shipped in Circutor LineEds (…

0.89exploit · 06 Oct, 19:44seclists.orgResearch

[0day-rubbish] Asustor ADM 3.5.9.RWM1 (AS602T) music.cgi act=live stored-filename command injection reaching system() (8.8 primary, PR:L)

Posted by disclosure via Fulldisclosure on Oct 06 0day Rubbish Research Team is publicly disclosing a vulnerability in the media handler of the ADM (ASUSTOR Data Master)…

0.89exploit · 06 Oct, 19:44seclists.orgResearch

SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06 SEC Consult Vulnerability Lab Research Announcement ================================================…

0.89exploit · 06 Oct, 09:00projectzero.google

How to fix a bug in a fix

Project Zero often works with software vendors to remediate the vulnerabilities we report and provide broader guidance on making software more secure. Some vendors expre…

0.89exploit · 06 Oct, 00:18seclists.org

Fwd: [Freeipmi-announce] FreeIPMI 1.6.20 Released

Posted by Chad Dougherty on Oct 05 -------- Forwarded Message -------- Subject: [Freeipmi-announce] FreeIPMI 1.6.20 Released Date: Mon, 5 Oct 2026 20:56:51 +0000 From: C…

0.86critical · 06 Oct, 14:00cisa.gov

Hitachi Energy REB500

View CSAF Summary Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can …