Loki Intelligence — Security Briefs · Published

Daily Security Brief: Kernel Risk, Supply Chain Malware, and Phishing Kits

Today’s reporting highlights risk across core infrastructure, developer ecosystems, and identity platforms. Teams should prioritize patch visibility, dependency controls, phishing resistance, and monitoring for compromised edge and consumer-linked devices.

Signal 01 · The Hacker News

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

A Linux kernel vulnerability dubbed Bad Epoll can allow local unprivileged users to gain root-level control, with impact spanning servers, desktops, and Android-based systems. Fixes are reportedly available.

Why it matters: Security and engineering teams should confirm kernel and Android patch status, especially on shared hosts, developer workstations, and fleet-managed devices where local access could become full compromise.

Source: The Hacker News

Signal 02 · The Hacker News

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Researchers identified Avalon, a modular malware framework delivered through phishing and designed to combine credential theft, remote access, movement across environments, and ransomware-like disruption.

Why it matters: Defenders should treat phishing detections as potential full intrusion starts, validating email controls, endpoint behavior analytics, credential protection, and backup resilience together rather than separately.

Source: The Hacker News

Signal 03 · The Hacker News

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

Seven vulnerabilities were disclosed in FatFs, a lightweight filesystem library widely used in embedded products to handle FAT and exFAT storage media. The findings may affect many devices because the component is broadly bundled into firmware.

Why it matters: Product teams should inventory embedded dependencies, request vendor impact statements, and assess exposure from removable media or storage parsing paths in devices already deployed.

Source: The Hacker News

Signal 04 · BleepingComputer

NetNut proxy network disrupted, 2 million infected devices cut off

A coordinated disruption involving Google reportedly severed NetNut’s access to around two million compromised Android devices used in a residential proxy network. Affected devices included smart TVs and streaming hardware.

Why it matters: Organizations should monitor for traffic from residential proxy infrastructure, strengthen fraud and abuse controls, and consider unmanaged Android and IoT devices as potential sources of suspicious network activity.

Source: BleepingComputer

Signal 05 · The Hacker News

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

North Korea-linked actors were tied to malicious npm packages impersonating Rollup-related polyfill tooling, with the goal of enabling access and stealing developer secrets.

Why it matters: Engineering teams should enforce package provenance checks, lockfile review, secret scanning, and least-privilege developer tokens to reduce blast radius from dependency confusion or typosquatting.

Source: The Hacker News

Signal 06 · BleepingComputer

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

A phishing-as-a-service platform called ARToken appears connected to EvilTokens and exposes tooling focused on Microsoft 365 credential and session theft campaigns.

Why it matters: Identity teams should harden Microsoft 365 access with phishing-resistant MFA, conditional access, session controls, rapid token revocation processes, and user reporting workflows.

Source: BleepingComputer

Signal 07 · The Hacker News

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

A newly described actor, Armored Likho, has been linked to campaigns against government and power-sector organizations in Russia, Brazil, and Kazakhstan, using a stealer known as BusySnake.

Why it matters: Critical infrastructure and public-sector defenders should review credential theft detections, segment sensitive systems, and increase monitoring for targeted intrusion activity against administrative users.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.