Loki Intelligence — Security Briefs · Published
Daily Brief: npm Hardening, Defender Patch, AI Agent Risk
Today’s security news highlights practical governance and isolation controls, from npm’s safer defaults to GitHub’s repository ownership program. Teams should prioritize dependency hygiene, endpoint patching, AI tool sandboxing, and ICS exposure reduction.
Signal 01 · The Hacker News
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
npm 12 changes package installation behavior by disabling install scripts by default and moving away from token patterns that could weaken 2FA expectations. The shift is aimed at reducing common supply chain abuse paths in JavaScript ecosystems.
Why it matters: Engineering teams should test builds against npm 12 defaults, document any required script exceptions, and review token usage for least privilege and 2FA alignment.
Source: The Hacker News
Signal 02 · The Hacker News
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
A crypto wallet weakness dubbed Ill Bloom is reportedly being exploited to steal funds by abusing flawed recovery phrase generation in affected wallet software. Losses are already estimated in the millions.
Why it matters: Wallet providers should review entropy and recovery phrase generation controls, while users and custodians should follow vendor guidance and move funds only through trusted recovery processes.
Source: The Hacker News
Signal 03 · The Hacker News
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft released fixes for RoguePlanet, a Defender-related privilege escalation vulnerability tracked as CVE-2026-50656. The issue could allow elevated local access if left unpatched.
Why it matters: Security teams should confirm Microsoft Malware Protection Engine and Defender updates are deployed broadly, especially on endpoints used by developers, admins, and help desk staff.
Source: The Hacker News
Signal 04 · The Hacker News
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Research describes how AI coding agents used for security review can be manipulated into executing unsafe project code during analysis. The finding underscores that automated review tools can become part of the attack surface.
Why it matters: Run AI code agents in restricted sandboxes with no sensitive credentials, limited network access, and clear separation from developer workstations and production systems.
Source: The Hacker News
Signal 05 · GitHub Security
How GitHub gave every repository a durable owner
GitHub detailed an internal effort to assign durable, validated owners to active repositories and archive repositories without clear stewardship. The program turned ownership into a foundation for security and maintenance decisions.
Why it matters: Organizations should maintain clear repo ownership, archive abandoned code, and make ownership data enforceable for vulnerability response, access reviews, and service accountability.
Source: GitHub Security
Signal 06 · CISA
OpenPLC v3
CISA issued an advisory for OpenPLC v3 describing a vulnerability that could let an authenticated attacker write files and potentially reach native code execution through normal compilation behavior. The affected context is industrial control software.
Why it matters: Operators should restrict OpenPLC access, apply vendor fixes or mitigations, monitor authenticated activity, and avoid exposing engineering interfaces to untrusted networks.
Source: CISA
Signal 07 · CISA
Schneider Electric Easergy MiCOM Px40 Series
CISA published an advisory for Schneider Electric Easergy MiCOM Px40 Series protection relay products. The advisory notes a vendor-acknowledged vulnerability affecting equipment used in electrical protection environments.
Why it matters: Asset owners should review affected relay deployments, apply Schneider Electric guidance, segment protection networks, and verify remote access controls around substation assets.
Source: CISA
Brief sources
Related briefs
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
- MCP Security Testing Checklist
Relevant Loki service: AI Agent Risk Assessment — Private Preview.