Loki Intelligence — Security Briefs · Published
Daily Security Brief: Critical Infrastructure, Phishing, Joomla, Android
Today’s security coverage centers on exposed edge devices, identity phishing, vulnerable CMS extensions, and mobile malware gaining higher device access. Teams should prioritize router hardening, phishing-resistant authentication, rapid CMS patching, and tighter Android device controls.
Signal 01 · BleepingComputer
US and allies warn of Russian critical infrastructure attacks
Cyber agencies from the U.S. and partner countries warned that Russian state-linked actors are targeting vulnerable and poorly configured routers used by critical infrastructure organizations.
Why it matters: Inventory internet-facing network gear, remove default or weak configurations, apply firmware updates, restrict management access, and monitor for unusual router-to-internal network activity.
Source: BleepingComputer
Signal 02 · The Hacker News
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
A public misconfiguration exposed details tied to multiple Evilginx-based Microsoft 365 phishing operations, highlighting continued attacker focus on stealing cloud identity sessions.
Why it matters: Use phishing-resistant MFA where possible, monitor for impossible travel and new device sessions, shorten session lifetimes for risky users, and train teams to report suspicious Microsoft 365 sign-in pages.
Source: The Hacker News
Signal 03 · The Hacker News
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
CISA added severe Joomla extension vulnerabilities affecting iCagenda and Balbooa Forms to its exploited vulnerabilities catalog after reports of in-the-wild abuse.
Why it matters: Find affected Joomla sites, update or disable vulnerable extensions, review web logs for suspicious activity, and ensure CMS admin panels are protected with least privilege and strong authentication.
Source: The Hacker News
Signal 04 · BleepingComputer
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
BleepingComputer published a relevant security update.
Why it matters: Review exposure, ownership, and remediation priority for systems that match this signal.
Source: BleepingComputer
Signal 05 · BleepingComputer
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
BleepingComputer published a relevant security update.
Why it matters: Review exposure, ownership, and remediation priority for systems that match this signal.
Source: BleepingComputer
Signal 06 · BleepingComputer
RedHook Android malware now uses Wireless ADB for shell access
A newer RedHook Android malware variant reportedly abuses wireless debugging features to obtain deeper device access without needing a physical computer connection.
Why it matters: For managed Android fleets, disable developer options where possible, block untrusted app installs, enforce mobile threat defense, and alert on devices with debugging features enabled.
Source: BleepingComputer
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.