Loki Intelligence — Security Briefs · Published

Daily Security Brief: Exploited Edge Apps, AI Agent Risk, and Recovery Updates

Today’s risk is concentrated around internet-facing collaboration, webmail, remote access, and application platforms where newly disclosed or recently patched flaws are moving into attacker workflows. Teams should prioritize exposure review, rapid patching, stronger monitoring, and tighter controls around AI agent extensions and recovery readiness.

Signal 01 · The Hacker News

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Researchers report scanning and exploitation attempts against a critical flaw affecting Gitea Docker images shortly after public disclosure. The issue highlights how quickly development infrastructure becomes a target once patches and advisories are available.

Why it matters: Inventory exposed Gitea instances, confirm patched container images are deployed, rotate sensitive credentials if compromise is suspected, and monitor for unusual repository or CI activity.

Source: The Hacker News

Signal 02 · The Hacker News

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

The weekly roundup covers a mix of ordinary technologies being abused, including consumer devices, browser prompts, fake proof-of-concept code, and AI-related tricks. The common theme is attackers exploiting trust in familiar workflows and low-friction user actions.

Why it matters: Security programs should treat demos, browser permissions, third-party code samples, and unmanaged devices as real attack surfaces, not edge cases.

Source: The Hacker News

Signal 03 · BleepingComputer

Max severity Adobe ColdFusion flaw now exploited in attacks

A maximum-severity Adobe ColdFusion vulnerability is now reportedly being exploited in attacks. Organizations running ColdFusion should assume internet-facing systems are under heightened scrutiny.

Why it matters: Patch urgently, restrict administrative exposure, review server logs for abnormal access, and validate that ColdFusion instances are covered by asset management and detection rules.

Source: BleepingComputer

Signal 04 · The Hacker News

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Academic researchers described a technique for disguising malicious skills used by AI coding agents so they can evade some static scanning approaches. The finding underscores that agent ecosystems are developing software supply chain risks similar to plugins and packages.

Why it matters: Require trusted sources for AI agent skills, use runtime controls in addition to static checks, limit agent permissions, and review what code or secrets agents can access.

Source: The Hacker News

Signal 05 · The Hacker News

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

A suspected China-aligned activity cluster is targeting university departments by exploiting patched Roundcube webmail vulnerabilities. The campaign appears focused on academic environments tied to technical research fields.

Why it matters: Universities and research organizations should patch Roundcube, reduce webmail exposure where possible, strengthen mailbox monitoring, and watch for suspicious authentication or forwarding changes.

Source: The Hacker News

Signal 06 · BleepingComputer

BeyondTrust warns of critical flaws in remote access software

BeyondTrust warned customers about critical vulnerabilities in Remote Support and Privileged Remote Access products that could allow authentication bypass. Remote access platforms remain high-value targets because they can provide broad operational reach.

Why it matters: Apply vendor updates quickly, restrict management interfaces, audit privileged sessions, and review access logs for unusual support or administrative activity.

Source: BleepingComputer

Signal 07 · BleepingComputer

Microsoft testing new Cloud Rebuild Windows 11 recovery feature

Microsoft is testing a Windows 11 Cloud Rebuild recovery capability in Insider builds. The feature could give IT teams another option for restoring systems when local recovery paths are damaged or unavailable.

Why it matters: Evaluate recovery features alongside backup, endpoint management, and incident response plans so rebuild workflows are tested before outages or destructive attacks occur.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki service: AI Agent Risk Assessment — Private Preview.