Loki Intelligence — Security Briefs · Published

Daily Security Brief: KEV Updates, AI Abuse, and Critical Patches

Patch urgency is high this week, with CISA adding exploited flaws to KEV and vendors shipping critical fixes for Zoom, browsers, Adobe, and VMware. AI tooling also remains a growing operational risk, both as an attacker aid and as a source of new defensive workflow challenges.

Signal 01 · CISA

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two actively exploited vulnerabilities to its KEV catalog, covering KNX protocol authorization behavior and Oracle E-Business Suite improper access control. Federal agencies must remediate on deadline, and private-sector teams should treat the additions as high-priority signals.

Why it matters: Use KEV changes to drive emergency patch review, exposure checks, and compensating controls for internet-facing or business-critical systems.

Source: CISA

Signal 02 · The Hacker News

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

Zoom released Windows updates for a critical flaw that could allow account takeover across several Zoom client products. Organizations using Zoom Workplace or VDI on Windows should validate version coverage quickly.

Why it matters: Prioritize endpoint software update enforcement, especially for collaboration tools that hold identity, meeting, chat, and file-sharing access.

Source: The Hacker News

Signal 03 · BleepingComputer

Google Gemini CLI abused as a hacking agent, malware botnet operator

Researchers reported that a threat actor used Google’s open-source Gemini CLI as part of malicious operations, including automation support and botnet activity. The case highlights how general-purpose AI developer tools can be repurposed inside attacker workflows.

Why it matters: Monitor AI tool usage in developer and admin environments, set acceptable-use controls, and review logs for unusual automation patterns.

Source: BleepingComputer

Signal 04 · BleepingComputer

We built a vulnerability vending machine: AI tokens in, zero-days out

Intruder described an AI-assisted vulnerability discovery system that combines code analysis techniques with large language models. The research reportedly uncovered previously unknown issues, including in WordPress plugin code under responsible disclosure.

Why it matters: Assume vulnerability discovery cycles are accelerating and strengthen secure code review, dependency governance, and intake processes for disclosure reports.

Source: BleepingComputer

Signal 05 · The Hacker News

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

Mozilla, Google, Adobe, and VMware issued updates addressing multiple serious vulnerabilities, including critical Firefox flaws with public exploit information. The breadth of affected products makes this a broad enterprise patching event.

Why it matters: Coordinate browser, creative software, and virtualization patching through endpoint management, and verify update success rather than relying on auto-update assumptions.

Source: The Hacker News

Signal 06 · The Hacker News

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

The article argues that traditional SASE traffic inspection is struggling to capture risk in browser-first, SaaS-heavy, AI-enabled workflows. Sensitive data movement may now happen through application context that packet inspection alone cannot fully interpret.

Why it matters: Evaluate controls for browser activity, SaaS permissions, AI prompts, and data flows rather than relying solely on network-layer inspection.

Source: The Hacker News

Signal 07 · The Hacker News

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

A researcher released proof-of-concept details for a Windows elevation-of-privilege issue shortly after Patch Tuesday. Public discussion increases pressure on defenders to watch for vendor guidance and short-term mitigation options.

Why it matters: Track Microsoft advisories, restrict local admin exposure, and monitor privilege escalation indicators while awaiting formal remediation.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.