Loki Intelligence — Security Briefs · Published

Daily Brief: AI Agent, Browser, and Air-Gap Security Risks

Research today highlights how trusted tooling layers, from AI coding agents to browser mods, can become new delivery and data-theft paths. Teams should strengthen software provenance, runtime monitoring, extension governance, and controls for sensitive isolated systems.

Signal 01 · The Hacker News

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Researchers showed that malicious add-on skills for AI coding agents can be packaged in ways that make static detection unreliable while preserving harmful behavior.

Why it matters: Do not rely only on static scanning for AI agent extensions; add provenance checks, sandboxed execution, behavior monitoring, and approval workflows for new skills.

Source: The Hacker News

Signal 02 · The Hacker News

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

Academic researchers described TrojPix, a side-channel concept that can leak information from isolated machines through subtle display-related emissions.

Why it matters: High-security environments should reassess air-gap assumptions, use shielding and physical separation where needed, and monitor sensitive systems for unauthorized display or cable changes.

Source: The Hacker News

Signal 03 · The Hacker News

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

QuimaRAT is a newly reported Java-based remote access trojan marketed as malware-as-a-service and built to target Windows, Linux, and macOS systems.

Why it matters: Cross-platform malware reduces the value of OS-specific assumptions; standardize endpoint telemetry, Java runtime controls, and detections across all desktop and server fleets.

Source: The Hacker News

Signal 04 · The Hacker News

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

Researchers found an Opera GX issue that could allow a hostile site to install a browser mod and access selected data from pages the user later visited.

Why it matters: Treat browser mods and extensions as privileged software: enforce update policies, restrict installation sources, and maintain an inventory of approved add-ons.

Source: The Hacker News

Signal 05 · BleepingComputer

Flipper Zero firmware development continues with community help

Flipper Devices said Flipper Zero firmware work will continue with a smaller internal team and more community involvement.

Why it matters: Organizations that allow or test with community-driven device firmware should verify release authenticity, track changes, and define clear rules for approved builds.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki service: AI Agent Risk Assessment — Private Preview.