Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

AI stack threats surge across agents, platforms, and developer tooling

Today’s activity highlights attackers moving quickly against AI-adjacent systems, from ServiceNow and Langflow to coding agents and GitHub supply chains. Teams should prioritize patching exposed platforms, isolating AI workloads, and tightening trust boundaries around developer automation.

Signal 01 · The Hacker News

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Sysdig researchers report that the JADEPUFFER operator has expanded activity against Langflow environments with ENCFORGE, ransomware aimed at AI-related files and assets.

Why it matters: Treat AI orchestration servers as high-value infrastructure: patch quickly, restrict internet exposure, monitor unusual file changes, and keep recoverable offline backups of models and datasets.

Source: The Hacker News

Signal 02 · BleepingComputer

JadePuffer agentic attacks now target AI model data with ransomware

BleepingComputer details how JadePuffer has added custom malware that targets training data, vector stores, and model checkpoints rather than only traditional business files.

Why it matters: Security teams should include AI artifacts in backup, integrity monitoring, and incident response plans, since model loss or tampering can disrupt product delivery and trust.

Source: BleepingComputer

Signal 03 · BleepingComputer

Critical ServiceNow code execution flaw now exploited in attacks

Active exploitation has been reported for CVE-2026-6875, a critical ServiceNow AI Platform code execution vulnerability.

Why it matters: Organizations using ServiceNow AI Platform should verify remediation status, review access logs for suspicious activity, and apply compensating controls where patching is delayed.

Source: BleepingComputer

Signal 04 · The Hacker News

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers are increasingly scanning for WordPress sites affected by the paired wp2shell vulnerabilities after public exploit availability accelerated abuse.

Why it matters: Web teams should update affected components, remove unused plugins and themes, enable web application monitoring, and look for unexpected admin accounts or file changes.

Source: The Hacker News

Signal 05 · The Hacker News

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

The Hacker News also reports in-the-wild abuse of the critical ServiceNow AI Platform flaw, underscoring that exploitation is no longer theoretical.

Why it matters: Duplicate reporting from multiple outlets increases confidence in urgency; asset owners should confirm exposure, patch level, and incident review coverage immediately.

Source: The Hacker News

Signal 06 · BleepingComputer

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Researchers found sandbox escape issues across several AI coding tools where files produced by agents could later be trusted by host-side processes.

Why it matters: Engineering teams should update affected tools, separate agent workspaces from trusted execution paths, and review automation that runs generated files without human approval.

Source: BleepingComputer

Signal 07 · The Hacker News

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

The FakeGit campaign seeded thousands of malicious GitHub repositories, including many posing as AI skills or MCP servers, to distribute SmartLoader malware.

Why it matters: Developers should validate repository reputation, pin dependencies, avoid running unknown setup scripts, and route new AI tooling through security review before adoption.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki service: Orvyn — AI agent security private preview.