Loki Intelligence — Security Briefs · Published

Daily Security Brief: Edge Devices, AI Platforms, and Supply Chain Risk

Attackers are continuing to focus on internet-facing platforms, VPN appliances, and widely deployed infrastructure where patch delays create high impact exposure. Software supply chain and AI ecosystem incidents also show why teams need stronger dependency controls, release validation, and monitoring around developer workflows.

Signal 01 · BleepingComputer

Critical ServiceNow code execution flaw now exploited in attacks

A critical ServiceNow AI Platform vulnerability is reportedly being exploited in the wild. Organizations using affected ServiceNow components should treat this as an urgent exposure review and patching priority.

Why it matters: Inventory ServiceNow instances, confirm vendor fixes are applied, restrict administrative access, and review logs for unusual activity around platform configuration or automation features.

Source: BleepingComputer

Signal 02 · The Hacker News

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

Hugging Face disclosed an incident involving an autonomous AI agent targeting production systems. The case highlights that AI platforms and automation tooling are now both operational assets and security targets.

Why it matters: Security teams should review secrets handling, model and dataset publishing workflows, agent permissions, and production access boundaries for AI development environments.

Source: The Hacker News

Signal 03 · The Hacker News

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 released fixes for a critical NGINX flaw that can crash worker processes and may have more severe impact under certain conditions. Updated stable and mainline versions are available.

Why it matters: Prioritize patching internet-facing NGINX deployments, validate package sources, monitor for abnormal worker crashes, and ensure load balancers or WAFs do not mask underlying service instability.

Source: The Hacker News

Signal 04 · The Hacker News

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Researchers identified three malicious RubyGems packages linked to a supply chain campaign called SleeperGem. The packages were designed to compromise developer machines and retrieve additional components.

Why it matters: Engineering teams should pin dependencies, audit recent gem additions, use trusted package allowlists where feasible, and monitor developer endpoints for unexpected network or credential access.

Source: The Hacker News

Signal 05 · BleepingComputer

Hackers abuse ViPNet software to target Russian govt agencies

A threat actor is reportedly abusing the update mechanism of ViPNet private networking software to target Russian organizations, including government agencies. The activity demonstrates continued interest in trusted update channels.

Why it matters: Organizations should verify update integrity, monitor vendor update traffic, separate management networks, and maintain detection for unexpected changes to VPN or private networking tools.

Source: BleepingComputer

Signal 06 · The Hacker News

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

CERT-UA reported that UAC-0145 is using ClickFix-style lures to trick Ukrainian targets into running actions that lead to malware infection. The campaign relies on social engineering rather than purely technical compromise.

Why it matters: Defenders should reinforce user guidance against copying commands from web prompts, add detections for suspicious script execution, and harden endpoint controls for high-risk user groups.

Source: The Hacker News

Signal 07 · The Hacker News

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

SonicWall SMA 1000 series VPN appliances were reportedly exploited as zero-days before public disclosure, with attackers gaining high-level access on affected devices. The activity has been linked to a previously undocumented threat actor.

Why it matters: Treat exposed VPN appliances as high-value assets: apply fixes, rotate credentials and keys where appropriate, review appliance logs, and look for signs of persistence or unauthorized administrative changes.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: AI Agent Risk Assessment — Private Preview and web & API security review.