Loki Intelligence — Security Briefs · Published
Daily Security Brief: Patch 7-Zip, WordPress, and Watch Stealer Activity
Today’s priority is rapid patching for widely used software, with 7-Zip and WordPress Core both facing heightened risk from remote code execution flaws. Security teams should also tighten credential protections amid increased ACR Stealer activity and review privacy controls for age verification systems.
Signal 01 · BleepingComputer
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip 26.02 addresses a remote code execution flaw that can be triggered through malicious compressed files opened by a user. The risk is higher in environments where archives arrive through email, chat, ticketing systems, or file-sharing workflows.
Why it matters: Prioritize updating 7-Zip on endpoints and servers, and reinforce controls that scan, sandbox, or quarantine untrusted archives before users open them.
Source: BleepingComputer
Signal 02 · BleepingComputer
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft reports increased ACR Stealer activity targeting enterprise customers to collect browser passwords, authentication tokens, and sensitive files. This type of malware can quickly turn one infected device into broader account and data exposure.
Why it matters: Reduce stored browser secrets, enforce phishing-resistant MFA where possible, monitor token misuse, and ensure endpoint detection covers credential theft behaviors.
Source: BleepingComputer
Signal 03 · BleepingComputer
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploit code is now available for critical WordPress Core “wp2shell” remote code execution vulnerabilities. Sites that remain unpatched are more likely to face automated scanning and opportunistic compromise attempts.
Why it matters: Patch WordPress Core urgently, verify backups, review web server logs for unusual activity, and restrict administrative access with MFA and least privilege.
Source: BleepingComputer
Signal 04 · BleepingComputer
The Future of Age Verification: Your Face Never Leaves Your Device
Incode describes an on-device age estimation model designed to verify age without transmitting or storing facial images. The approach aims to help organizations meet age-check requirements while reducing biometric data exposure.
Why it matters: Product and compliance teams should evaluate privacy-preserving verification options that minimize sensitive data collection, retention, and third-party transfer risk.
Source: BleepingComputer
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.