
HAIJA INTEL REPORT
Tweets / X
6 items








Regular sources
9 itemsRussian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
Knot Resolver 6.3.0 DNS-over-QUIC heap buffer overflow (RCE)
Posted by Przemyslaw Frasunek on Jul 23 Hello, The following is a report of a remotely triggerable heap buffer overflow in Knot Resolver's DNS-over-QUIC (DoQ) receive pa…
Email threat landscape: Q2 2026 trends and insights
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phi…
Serendipity blog software security fixes in 2.6.1 (Username takeover, XSS, ...)
Posted by Hanno Böck on Jul 23 Hi, From the release notes of Serendipity 2.6.1, a PHP-based open source blog system: "It has been a while that we had to publish a securi…
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a crit…
A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits
Posted by zz lin on Jul 22 I came across a project, "0day Rubbish", that states it will continuously https://0day-rubbish.com/blog...
Synology stale DNS allows practical interception of traffic from vulnerable DSM clients
Posted by shed riot on Jul 22 # Synology stale DNS allows practical interception of traffic from vulnerable DSM clients Vendor case: 904909 Suggested severity: High ## C…
Johnson Controls C-CURE 9000 and Victor application server
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions o…
Amplitude customers using domain proxies should update their configuration immediately.
Posted by shed riot on Jul 22 After receiving live analytics requests intended for `api2.amplitude.com`, I contacted `security () amplitude com` and was invited to submi…