Loki Intelligence — Security Briefs · Published

Daily Security Brief: Critical Infrastructure, Phishing, Joomla, Android

Today’s security coverage centers on exposed edge devices, identity phishing, vulnerable CMS extensions, and mobile malware gaining higher device access. Teams should prioritize router hardening, phishing-resistant authentication, rapid CMS patching, and tighter Android device controls.

Signal 01 · BleepingComputer

US and allies warn of Russian critical infrastructure attacks

Cyber agencies from the U.S. and partner countries warned that Russian state-linked actors are targeting vulnerable and poorly configured routers used by critical infrastructure organizations.

Why it matters: Inventory internet-facing network gear, remove default or weak configurations, apply firmware updates, restrict management access, and monitor for unusual router-to-internal network activity.

Source: BleepingComputer

Signal 02 · The Hacker News

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

A public misconfiguration exposed details tied to multiple Evilginx-based Microsoft 365 phishing operations, highlighting continued attacker focus on stealing cloud identity sessions.

Why it matters: Use phishing-resistant MFA where possible, monitor for impossible travel and new device sessions, shorten session lifetimes for risky users, and train teams to report suspicious Microsoft 365 sign-in pages.

Source: The Hacker News

Signal 03 · The Hacker News

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

CISA added severe Joomla extension vulnerabilities affecting iCagenda and Balbooa Forms to its exploited vulnerabilities catalog after reports of in-the-wild abuse.

Why it matters: Find affected Joomla sites, update or disable vulnerable extensions, review web logs for suspicious activity, and ensure CMS admin panels are protected with least privilege and strong authentication.

Source: The Hacker News

Signal 04 · BleepingComputer

OpenAI temporarily relaxes GPT-5.6 Sol usage limits

BleepingComputer published a relevant security update.

Why it matters: Review exposure, ownership, and remediation priority for systems that match this signal.

Source: BleepingComputer

Signal 05 · BleepingComputer

Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time

BleepingComputer published a relevant security update.

Why it matters: Review exposure, ownership, and remediation priority for systems that match this signal.

Source: BleepingComputer

Signal 06 · BleepingComputer

RedHook Android malware now uses Wireless ADB for shell access

A newer RedHook Android malware variant reportedly abuses wireless debugging features to obtain deeper device access without needing a physical computer connection.

Why it matters: For managed Android fleets, disable developer options where possible, block untrusted app installs, enforce mobile threat defense, and alert on devices with debugging features enabled.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.