Loki Intelligence — Security Briefs · Published

Daily Brief: AI Tenant Isolation, KEV Updates, and ICS Risk

AI platforms remain a major focus as researchers report patched flaws affecting tenant isolation, chatbot agent boundaries, and code-generation supply chains. CISA also added actively exploited vulnerabilities to KEV, while infrastructure and governance updates highlight the need for faster remediation and stronger accountability.

Signal 01 · The Hacker News

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Researchers disclosed a patched Writer AI vulnerability that could have exposed session tokens across tenant boundaries through agent preview behavior. The issue underscores how AI workflow features can weaken isolation if preview and execution contexts are not tightly separated.

Why it matters: Review AI vendor tenancy controls, session handling, and preview environments; require evidence of isolation testing for enterprise AI platforms.

Source: The Hacker News

Signal 02 · CISA

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to the KEV catalog, including issues affecting JoomShaper SP Page Builder and Langflow, based on observed exploitation. KEV inclusion signals that attackers are already using these weaknesses in real environments.

Why it matters: Prioritize asset discovery, patch validation, and compensating controls for affected products according to KEV timelines.

Source: CISA

Signal 03 · CISA

CISA Adds One Known Exploited Vulnerability to Catalog

CISA separately added an Adobe ColdFusion path traversal vulnerability to KEV after evidence of active exploitation. Internet-facing ColdFusion systems should be treated as high priority for remediation and monitoring.

Why it matters: Confirm ColdFusion exposure, apply vendor fixes, and monitor for unusual file access, authentication anomalies, and web server activity.

Source: CISA

Signal 04 · The Hacker News

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

A patched Google Dialogflow CX flaw could have allowed a user with edit access to one Code Block-enabled agent to impact other enabled agents in the same cloud project. Potential exposure included chatbot conversations and sensitive agent data.

Why it matters: Segment chatbot projects, limit agent edit permissions, and audit service boundaries for AI features that execute code or access live data.

Source: The Hacker News

Signal 05 · The Hacker News

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

The article examines how AI-generated code changes software supply chain risk by adding new sources of dependencies, generated logic, and review gaps. Traditional SBOM and dependency controls may not fully capture AI-assisted development behavior.

Why it matters: Update secure SDLC controls for AI coding tools, including provenance, human review, dependency checks, and policy enforcement in CI/CD.

Source: The Hacker News

Signal 06 · Cloudflare Security

Cloudflare proudly joins the UK government's Cyber Resilience Pledge

Cloudflare announced participation in the UK government's Cyber Resilience Pledge, a voluntary framework focused on governance, board accountability, and supply chain security. The pledge reflects growing expectations that cyber resilience be managed as an executive risk.

Why it matters: Use resilience frameworks to benchmark board reporting, third-party risk management, and baseline controls across business units.

Source: Cloudflare Security

Signal 07 · CISA

Hitachi Energy e-mesh EMS

CISA published an ICS advisory for a buffer overflow vulnerability in Hitachi Energy e-mesh EMS that could affect application availability. The impacted product supports energy management environments where outages can have operational consequences.

Why it matters: Coordinate with OT owners to assess exposure, schedule vendor remediation, and validate segmentation and monitoring for energy management systems.

Source: CISA

Brief sources

Related briefs

Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.