Official intelligence summary

HAIJA INTEL REPORT

Generated 31/07/2026, 09:40. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources4
Tweets / X11
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

11 items
H4
h4x0r_dz @h4x0r_dz
30 Jul, 09:49 · core
0.72
H4x0r.DZ @h4x0r_dz · 23h GitHub - Zer0SumGam3/CVE-2026-66066-POC: PoC for CVE-2026-66066 in Ruby on Rails From github.com 1 21 127 10K
@SpecterOps avatar
SpecterOps @SpecterOps
30 Jul, 21:33 · core
0.62
AI agents are becoming a new layer of enterprise identity. They can access data & execute workflows, thus they also create new attack paths. @elad_shamir explores how BloodHound Enterprise extends Attack Path Management to Microsoft Entra Agent ID.
tweet media
@nahamsec avatar
nahamsec @nahamsec
30 Jul, 01:49 · core
0.44
Just casually dropping an 0day like an absolute legend! #cosmic We reported KindaRails2Shell, a critical RCE in Ruby on Rails via Active Storage. It’s not a one-shot RCE, but the preconditions are kinda common under default configurations. Patch your applications now! https:// et
tweet media
@vxunderground avatar
vxunderground @vxunderground
30 Jul, 03:00 · secondary
0.41
Y'know, peace and love to my fellow stinky nerds, but someone really needs to sit down and explain to people what exact RCE means. The acronym Remote Code Execution implies code (the beep boop stuff) is remotely (far away) executed (ran on the computer). Hence, beep boop stuff
tweet mediatweet media
@SpecterOps avatar
SpecterOps @SpecterOps
30 Jul, 23:02 · core
0.40
Still haven't joined the #BloodHoundUnleashed Attack Path Championship? Start now, then visit Kennel Club during #BHUSA for bonus codes that could move you up the leaderboard. Password: LeadThePack Get started https:// unleashed.bloodhound.quest
tweet mediatweet media
@Unit42_Intel avatar
Unit42_Intel @Unit42_Intel
30 Jul, 19:33 · secondary
0.38
We analyzed an AI enabled hacking campaign by a Chinese-speaking threat actor. The adversary targeted infrastructure across seven vulnerabilities, combining autonomous AI driven enumeration with manual exploitation. Read our analysis: https:// bit.ly/4xg1bP2
tweet mediatweet media
@SentinelOne avatar
SentinelOne @SentinelOne
30 Jul, 21:54 · secondary
0.35
The S1 Advantage. On display at Black Hat. Booth #2933. August 4 - 6, Las Vegas. → Blurred Lines 3.0 at Caramá: an executive briefing on geopolitical flashpoints, weaponized AI, and what security leaders must do to adapt. August 4. https:// go.sentinelone.com/blackhat-26-bl urre…
tweet media
@_xpn_ avatar
_xpn_ @_xpn_
30 Jul, 23:34 · core
0.32
This is dope AF! Didn't think the research would go far, but glad that it started a good conversation. Thanks @danonit and @riskybiz . @HackingLZ and @_xpn_ out there, thought leader'ing... Meet us at Blackhat for free a free thought, we don't have a booth unfortunately, probably
@PortSwiggerRes avatar
PortSwiggerRes @PortSwiggerRes
30 Jul, 16:48 · core
0.32
In "Can AI Do Novel Security Research?" I'll share: - A research-machine blueprint for AI enthusiasts - Clearly defined AI fail-points for AI dodgers - Extensive insight into what makes security research work - Many many novel desync goodies I'll also publish major updates to
tweet mediatweet media
@Bugcrowd avatar
Bugcrowd @Bugcrowd
30 Jul, 16:11 · secondary
0.31
Don't blink now. https:// x.com/0xacb/status/2 082484609820823929 … We reported KindaRails2Shell, a critical RCE in Ruby on Rails via Active Storage. It’s not a one-shot RCE, but the preconditions are kinda common under default configurations. Patch your applications now! https:/
tweet mediatweet media
@gynvael avatar
gynvael @gynvael
30 Jul, 18:43 · secondary
0.29
New Pwndbg release! Added exithandlers cmd, kernel debug improvements + new cmds, support for glibc 2.43 heap dumping, track-heap --where, richer procinfo output (e.g. see those chromium/firefox pipe pairs!) & MORE! https:// github.com/pwndbg/pwndbg/ releases/tag/2026.07.29 … Spo
tweet mediatweet media

Regular sources

4 items
1.00exploit · 30 Jul, 21:41seclists.org

Re: 33 Vulnerabilities in cJSON

Posted by Collin Funk on Jul 30 Alan Coopersmith writes: Complaining about free software maintainers, who are presumably not funded by the projects (some certainly being…

0.89exploit · 30 Jul, 23:43seclists.org

Some Changes to GNOME Security Tracking

Posted by Alan Coopersmith on Jul 30 https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/ announces some changes to the GNOME project's…

0.86critical · 30 Jul, 14:00cisa.gov

Toptech Systems RCU II+ and Multiload II+

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected netwo…