Loki Intelligence — Security Briefs · Published

Daily Brief: Active Exploitation, SAP, Entra, SharePoint, and ABB Updates

Today’s brief is led by active exploitation warnings from CISA, including KEV additions and new SharePoint hardening guidance. SAP, Microsoft Entra ID, and multiple ABB industrial advisories also point to patching, monitoring, and configuration review priorities.

Signal 01 · CISA

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA added four actively exploited vulnerabilities to the KEV catalog, covering SonicWall SMA1000, Microsoft AD FS, and other affected technologies. Federal agencies must remediate on deadline, and private-sector teams should treat the list as a high-priority patch queue.

Why it matters: Prioritize asset discovery, exposure checks, vendor fixes, and compensating controls for any affected systems, especially internet-facing appliances and identity infrastructure.

Source: CISA

Signal 02 · CISA

ABB Ability Edgenius

CISA published an advisory for ABB Ability Edgenius covering a publicly reported vulnerability with an available update. Organizations using affected versions should review vendor guidance and validate deployment impact before updating operational environments.

Why it matters: Industrial teams should maintain an accurate inventory, test fixes where possible, and limit network reachability to reduce exposure while updates are planned.

Source: CISA

Signal 03 · The Hacker News

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP’s July security release includes a critical NetWeaver Application Server ABAP flaw that could affect sensitive data if left unpatched. The update set also addresses several other SAP product vulnerabilities.

Why it matters: SAP systems often support core business processes, so teams should prioritize patch validation, restrict administrative access, and watch for unusual data access or application behavior.

Source: The Hacker News

Signal 04 · The Hacker News

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

Researchers report that threat actors are abusing OAuth client ID spoofing techniques to validate stolen Microsoft Entra credentials while reducing visibility in some telemetry. The activity highlights gaps that can appear when identity events are not correlated across systems.

Why it matters: Security teams should strengthen conditional access, enforce phishing-resistant MFA where feasible, monitor anomalous OAuth activity, and correlate sign-in, app, and token signals.

Source: The Hacker News

Signal 05 · CISA

ABB Advant Master Online Builder

CISA issued an ABB Advant Master Online Builder advisory involving affected product media and an available update. Operators should confirm whether their installed or distributed versions match ABB’s affected guidance.

Why it matters: For engineering workstations and control-system tooling, verify software provenance, apply vendor updates, and restrict access to trusted personnel and networks.

Source: CISA

Signal 06 · CISA

ABB T-MAC Plus

CISA released an advisory for ABB T-MAC Plus covering vulnerabilities that could allow compromise of affected systems. ABB has provided updates for the reported issues.

Why it matters: Assess where T-MAC Plus is deployed, apply updates through change control, and use segmentation and monitoring to limit potential operational impact.

Source: CISA

Signal 07 · CISA

CISA Urges SharePoint Hardening After New Exploitations

CISA warned of active exploitation affecting supported on-premises SharePoint Server versions and urged organizations to harden deployments. The alert focuses on unauthorized access risk in self-managed SharePoint environments.

Why it matters: Teams should rapidly apply Microsoft guidance, reduce external exposure, review access logs, and confirm incident-response readiness for collaboration platforms.

Source: CISA

Brief sources

Related briefs

Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.