Official intelligence summary

HAIJA INTEL REPORT

Generated 24/07/2026, 09:39. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources9
Tweets / X6
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

6 items
@h4x0r_dz avatar
h4x0r_dz @h4x0r_dz
23 Jul, 13:08 · core
0.70
wow Kimi K3 exploited the latest Redis server with a 0day it discovered. All it took was 27min with 32 agents. https:// github.com/berabuddies/re dis-poc …
tweet media
@intigriti avatar
intigriti @intigriti
23 Jul, 11:17 · secondary
0.43
Performing recon can take hours of your time... Recon-skills by @uphiago packages 169 offensive security skills into an AI-ready toolkit, covering everything from subdomain enumeration and vhost discovery to JS analysis and GitHub secrets, all tested across 600+ real targets
tweet mediatweet media
@vxunderground avatar
vxunderground @vxunderground
23 Jul, 03:35 · secondary
0.39
A colleague of mine notified me of actual super rare mega fuck off ultra malware identified in the wild. He said the malware is sophisticated (by my standards) and has proven to be incredibly difficult to reverse engineer. He asked if I felt like trying to bonk it with a stick.
tweet mediatweet media
@RedCanary avatar
RedCanary @RedCanary
23 Jul, 21:21 · secondary
0.34
Your July threat briefing is here! CastleLoader is abusing ClickFix lures and native Windows tools (i.e., finger.exe, curl.exe, Python) to drop various payloads... And Mac malware is out here pulling new obfuscation tricks. @techieStef and @ForensicITGuy unpack the July
tweet media
@nahamsec avatar
nahamsec @nahamsec
23 Jul, 21:00 · core
0.32
We're thrilled to welcome @hackinghub_io as an In-Kind Sponsor of Bug Bounty Village at DEF CON 34! Their ongoing support helps us create a space for hackers to connect, learn, and push boundaries. #defcon #bugbounty #bbv #bugbountyvillage
tweet media
@nahamsec avatar
nahamsec @nahamsec
23 Jul, 11:23 · core
0.32
It’s Thursday, Not bounty thursday but close enough, here’s a live hacking vlog! https:// youtube.com/watch?v=tJhuAI NZWQ0 … TLDR : Google invited me to Seoul for one of the most unique bug bounty events I've ever attended. I joined an invite-only group of security researchers at
tweet mediatweet media

Regular sources

9 items
1.00general · 23 Jul, 23:23darkreading.comAttack path

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.

1.00exploit · 23 Jul, 21:33seclists.orgRCE

Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE)

Posted by Przemyslaw Frasunek on Jul 23 Hello, The following is a report of a remotely triggerable heap buffer overflow in Knot Resolver's DNS-over-QUIC (DoQ) receive pa…

1.00general · 23 Jul, 17:00microsoft.comAttack pathResearch

Email threat landscape: Q2 2026 trends and insights

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phi…

1.00exploit · 23 Jul, 09:52seclists.orgResearch

Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...)

Posted by Hanno Böck on Jul 23 Hi, From the release notes of Serendipity 2.6.1, a PHP-based open source blog system: "It has been a while that we had to publish a securi…

1.00general · 23 Jul, 08:34thehackernews.comWild exploit

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a crit…

1.00exploit · 23 Jul, 04:03seclists.orgResearch

A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits

Posted by zz lin on Jul 22 I came across a project, "0day Rubbish", that states it will continuously https://0day-rubbish.com/blog...

1.00exploit · 23 Jul, 04:02seclists.org

Synology stale DNS allows practical interception of traffic from vulnerable DSM clients

Posted by shed riot on Jul 22 # Synology stale DNS allows practical interception of traffic from vulnerable DSM clients Vendor case: 904909 Suggested severity: High ## C…

0.97critical · 23 Jul, 14:00cisa.govRCE

Johnson Controls C-CURE 9000 and Victor application server

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions o…

0.89exploit · 23 Jul, 04:02seclists.org

Amplitude customers using domain proxies should update their configuration immediately.

Posted by shed riot on Jul 22 After receiving live analytics requests intended for `api2.amplitude.com`, I contacted `security () amplitude com` and was invited to submi…