Loki Intelligence — Security Briefs · Published
Daily Security Brief: Active Exploitation, Dev Tool Risk, and Wallet Theft
Threat activity this week centers on actively exploited web application flaws, authentication weaknesses, and software supply chain compromises affecting developer and crypto ecosystems. Teams should prioritize emergency patch review, dependency validation, and monitoring for suspicious account or package activity.
Signal 01 · CISA
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two unrestricted file upload vulnerabilities affecting iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
Why it matters: Treat KEV additions as urgent patch triggers; inventory affected CMS plugins and remove or isolate exposed instances until updates are confirmed.
Source: CISA
Signal 02 · BleepingComputer
Hackers exploit critical auth bypass in Gitea Docker image
Attackers are exploiting a critical authentication bypass in the official Gitea Docker image that can allow user impersonation, including administrator accounts.
Why it matters: Organizations running self-hosted Git services should update affected images, rotate sensitive tokens, and review admin actions and repository access logs.
Source: BleepingComputer
Signal 03 · The Hacker News
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
A weakness in recovery phrase generation, dubbed Ill Bloom, has reportedly enabled attackers to drain more than $5 million from cryptocurrency wallets.
Why it matters: Wallet providers should audit entropy and key-generation logic, while users of affected wallets should follow vendor migration guidance and protect recovery material.
Source: The Hacker News
Signal 04 · The Hacker News
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra released fixes for a critical stored XSS issue in the Classic Web Client that could allow malicious code to run in a user's session through crafted email content.
Why it matters: Patch Zimbra quickly, especially internet-facing mail systems, and increase monitoring for unusual mailbox rules, session activity, or credential misuse.
Source: The Hacker News
Signal 05 · BleepingComputer
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
A Ryuk ransomware affiliate pleaded guilty in the United States for compromising companies and deploying ransomware against victim networks.
Why it matters: Law enforcement action can disrupt crews, but ransomware risk remains; maintain tested backups, endpoint visibility, and rapid containment playbooks.
Source: BleepingComputer
Signal 06 · The Hacker News
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Injective Labs' SDK GitHub repository was compromised and used to publish a malicious npm package designed to steal cryptocurrency wallet secrets.
Why it matters: Engineering teams should pin and verify dependencies, audit recent installs, rotate exposed secrets, and require strong protections for publishing accounts.
Source: The Hacker News
Signal 07 · The Hacker News
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
Researchers detailed a chain of three patched OpenClaw AI assistant flaws that could expose credentials, escalate privileges, and execute code on a host system.
Why it matters: AI assistant integrations need the same hardening as other endpoint software: timely updates, least privilege, secret isolation, and close review of message-driven workflows.
Source: The Hacker News
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.