Loki Intelligence — Security Briefs · Published

Daily Security Brief: Active Exploitation, Dev Tool Risk, and Wallet Theft

Threat activity this week centers on actively exploited web application flaws, authentication weaknesses, and software supply chain compromises affecting developer and crypto ecosystems. Teams should prioritize emergency patch review, dependency validation, and monitoring for suspicious account or package activity.

Signal 01 · CISA

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two unrestricted file upload vulnerabilities affecting iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

Why it matters: Treat KEV additions as urgent patch triggers; inventory affected CMS plugins and remove or isolate exposed instances until updates are confirmed.

Source: CISA

Signal 02 · BleepingComputer

Hackers exploit critical auth bypass in Gitea Docker image

Attackers are exploiting a critical authentication bypass in the official Gitea Docker image that can allow user impersonation, including administrator accounts.

Why it matters: Organizations running self-hosted Git services should update affected images, rotate sensitive tokens, and review admin actions and repository access logs.

Source: BleepingComputer

Signal 03 · The Hacker News

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

A weakness in recovery phrase generation, dubbed Ill Bloom, has reportedly enabled attackers to drain more than $5 million from cryptocurrency wallets.

Why it matters: Wallet providers should audit entropy and key-generation logic, while users of affected wallets should follow vendor migration guidance and protect recovery material.

Source: The Hacker News

Signal 04 · The Hacker News

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra released fixes for a critical stored XSS issue in the Classic Web Client that could allow malicious code to run in a user's session through crafted email content.

Why it matters: Patch Zimbra quickly, especially internet-facing mail systems, and increase monitoring for unusual mailbox rules, session activity, or credential misuse.

Source: The Hacker News

Signal 05 · BleepingComputer

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

A Ryuk ransomware affiliate pleaded guilty in the United States for compromising companies and deploying ransomware against victim networks.

Why it matters: Law enforcement action can disrupt crews, but ransomware risk remains; maintain tested backups, endpoint visibility, and rapid containment playbooks.

Source: BleepingComputer

Signal 06 · The Hacker News

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Injective Labs' SDK GitHub repository was compromised and used to publish a malicious npm package designed to steal cryptocurrency wallet secrets.

Why it matters: Engineering teams should pin and verify dependencies, audit recent installs, rotate exposed secrets, and require strong protections for publishing accounts.

Source: The Hacker News

Signal 07 · The Hacker News

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Researchers detailed a chain of three patched OpenClaw AI assistant flaws that could expose credentials, escalate privileges, and execute code on a host system.

Why it matters: AI assistant integrations need the same hardening as other endpoint software: timely updates, least privilege, secret isolation, and close review of message-driven workflows.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.