Loki Intelligence — Security Briefs · Published
Daily Security Brief: AI Exposure, WordPress RCE, npm Malware
Today’s brief highlights continued attacker focus on exposed AI tooling, open-source supply chains, and high-impact platform vulnerabilities. Teams should prioritize internet-facing asset review, rapid patch assessment, dependency controls, and stronger secret handling.
Signal 01 · The Hacker News
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Researchers reported NadMesh, a Go-based botnet targeting publicly reachable AI and automation services to collect cloud credentials and Kubernetes tokens. The activity underscores how fast attackers are adapting to unmanaged AI infrastructure.
Why it matters: Inventory exposed AI services, restrict management interfaces, rotate any secrets found in logs or environments, and monitor for unusual cloud API and Kubernetes activity.
Source: The Hacker News
Signal 02 · The Hacker News
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A newly disclosed WordPress core issue, tracked under CVEs, may allow unauthenticated code execution under certain configurations, with public technical details now available. Sites using persistent object caching appear to have additional exposure considerations.
Why it matters: Treat WordPress as a high-priority patching target, review cache configurations, limit plugin and theme attack surface, and watch for unexpected file changes or new admin users.
Source: The Hacker News
Signal 03 · The Hacker News
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Seven malicious npm packages were found targeting the Vite ecosystem and using blockchain-based command infrastructure to deliver remote-access malware. The campaign shows continued abuse of familiar developer tooling names and package trust.
Why it matters: Enforce dependency review, lockfiles, package provenance checks, and automated malware scanning in CI before packages reach developer machines or production builds.
Source: The Hacker News
Signal 04 · BleepingComputer
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
BleepingComputer covered HollowByte, an OpenSSL-related denial-of-service issue that can cause excessive server memory use from minimal unauthenticated traffic. Internet-facing TLS services may be at risk if running affected builds.
Why it matters: Track vendor guidance, update OpenSSL-dependent services promptly, and ensure rate limiting, load shedding, and service monitoring are in place for public endpoints.
Source: BleepingComputer
Signal 05 · The Hacker News
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission ordered Google to provide rival AI assistants broader Android access to device sensors, screen context, and wake capabilities comparable to Gemini. The move may reshape mobile assistant permissions and privacy controls.
Why it matters: Product and mobile security teams should revisit permission models, consent flows, telemetry boundaries, and enterprise controls for AI assistants on managed Android devices.
Source: The Hacker News
Signal 06 · BleepingComputer
New Windows LegacyHive zero-day gives hackers admin privileges
A researcher disclosed LegacyHive, a Windows zero-day privilege escalation issue affecting current systems. Public availability raises the likelihood of rapid testing by criminal and opportunistic actors.
Why it matters: Harden local admin paths, monitor for suspicious privilege changes, apply Microsoft mitigations or patches when available, and reduce exposure from untrusted local code execution.
Source: BleepingComputer
Signal 07 · The Hacker News
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenian authorities reportedly detained a Russian traveler on a U.S. warrant tied to a REvil ransomware suspect, while lawyers claim mistaken identity. The case reflects ongoing international pressure around ransomware prosecutions.
Why it matters: Ransomware remains a law-enforcement priority; organizations should preserve incident evidence, maintain tested recovery plans, and ensure executive teams understand reporting obligations.
Source: The Hacker News
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.