Official intelligence summary

HAIJA INTEL REPORT

Generated 28/09/2026, 10:20. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources15
Tweets / X0
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.

Tweets / X

0 items

Regular sources

15 items
1.00general · 27 Sept, 09:47thehackernews.comRCEWild exploit

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on Septembe…

1.00exploit · 27 Sept, 06:13seclists.orgRCEResearch

openEQUELLA authenticated RCE chain(s)

Posted by evan via Fulldisclosure on Sep 26 SUMMARY: an authenticated deserialization vuln in openEQUELLA allows https://blog.evan.lat/posts/openeq/ openequella is an "o…

1.00exploit · 27 Sept, 06:12seclists.orgRCEResearch

[0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2)

Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in MultiTech Conduit AEP (models mtcdt / mtcdtip / mt…

1.00general · 26 Sept, 10:49thehackernews.comRCEWild exploit

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exp…

1.00general · 25 Sept, 16:44thehackernews.com

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the Ma…

0.91general · 25 Sept, 11:27securityweek.comAttack path

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesfor…

0.89exploit · 27 Sept, 06:16seclists.org

[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)

Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-071 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Te…

0.89exploit · 27 Sept, 06:162 mentionsseclists.org

[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-070 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Te… | Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-069 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Te…

0.89exploit · 27 Sept, 06:162 mentionsseclists.org

[SYSS-2026-068]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)

Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-068 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Te… | Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-067 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Te…

0.89exploit · 27 Sept, 06:12seclists.orgResearch

[0day-rubbish] Server Technology PRO3X PDU 030600 port_mux listener program override to root command execution (7.2)

Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in Server Technology (Legrand group) PRO3X series int…

0.89exploit · 27 Sept, 06:12seclists.orgResearch

[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)

Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in Logo Netsis NetOpenX REST 2.0.6.9 (also distribute…