Loki Intelligence — Security Briefs · Published
Daily Brief: AI Agent, Browser, and Air-Gap Security Risks
Research today highlights how trusted tooling layers, from AI coding agents to browser mods, can become new delivery and data-theft paths. Teams should strengthen software provenance, runtime monitoring, extension governance, and controls for sensitive isolated systems.
Signal 01 · The Hacker News
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Researchers showed that malicious add-on skills for AI coding agents can be packaged in ways that make static detection unreliable while preserving harmful behavior.
Why it matters: Do not rely only on static scanning for AI agent extensions; add provenance checks, sandboxed execution, behavior monitoring, and approval workflows for new skills.
Source: The Hacker News
Signal 02 · The Hacker News
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Academic researchers described TrojPix, a side-channel concept that can leak information from isolated machines through subtle display-related emissions.
Why it matters: High-security environments should reassess air-gap assumptions, use shielding and physical separation where needed, and monitor sensitive systems for unauthorized display or cable changes.
Source: The Hacker News
Signal 03 · The Hacker News
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
QuimaRAT is a newly reported Java-based remote access trojan marketed as malware-as-a-service and built to target Windows, Linux, and macOS systems.
Why it matters: Cross-platform malware reduces the value of OS-specific assumptions; standardize endpoint telemetry, Java runtime controls, and detections across all desktop and server fleets.
Source: The Hacker News
Signal 04 · The Hacker News
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Researchers found an Opera GX issue that could allow a hostile site to install a browser mod and access selected data from pages the user later visited.
Why it matters: Treat browser mods and extensions as privileged software: enforce update policies, restrict installation sources, and maintain an inventory of approved add-ons.
Source: The Hacker News
Signal 05 · BleepingComputer
Flipper Zero firmware development continues with community help
Flipper Devices said Flipper Zero firmware work will continue with a smaller internal team and more community involvement.
Why it matters: Organizations that allow or test with community-driven device firmware should verify release authenticity, track changes, and define clear rules for approved builds.
Source: BleepingComputer
Brief sources
Related briefs
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
- MCP Security Testing Checklist
Relevant Loki service: AI Agent Risk Assessment — Private Preview.