Loki Intelligence — Security Briefs · Published
AI stack threats surge across agents, platforms, and developer tooling
Today’s activity highlights attackers moving quickly against AI-adjacent systems, from ServiceNow and Langflow to coding agents and GitHub supply chains. Teams should prioritize patching exposed platforms, isolating AI workloads, and tightening trust boundaries around developer automation.
Signal 01 · The Hacker News
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Sysdig researchers report that the JADEPUFFER operator has expanded activity against Langflow environments with ENCFORGE, ransomware aimed at AI-related files and assets.
Why it matters: Treat AI orchestration servers as high-value infrastructure: patch quickly, restrict internet exposure, monitor unusual file changes, and keep recoverable offline backups of models and datasets.
Source: The Hacker News
Signal 02 · BleepingComputer
JadePuffer agentic attacks now target AI model data with ransomware
BleepingComputer details how JadePuffer has added custom malware that targets training data, vector stores, and model checkpoints rather than only traditional business files.
Why it matters: Security teams should include AI artifacts in backup, integrity monitoring, and incident response plans, since model loss or tampering can disrupt product delivery and trust.
Source: BleepingComputer
Signal 03 · BleepingComputer
Critical ServiceNow code execution flaw now exploited in attacks
Active exploitation has been reported for CVE-2026-6875, a critical ServiceNow AI Platform code execution vulnerability.
Why it matters: Organizations using ServiceNow AI Platform should verify remediation status, review access logs for suspicious activity, and apply compensating controls where patching is delayed.
Source: BleepingComputer
Signal 04 · The Hacker News
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are increasingly scanning for WordPress sites affected by the paired wp2shell vulnerabilities after public exploit availability accelerated abuse.
Why it matters: Web teams should update affected components, remove unused plugins and themes, enable web application monitoring, and look for unexpected admin accounts or file changes.
Source: The Hacker News
Signal 05 · The Hacker News
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
The Hacker News also reports in-the-wild abuse of the critical ServiceNow AI Platform flaw, underscoring that exploitation is no longer theoretical.
Why it matters: Duplicate reporting from multiple outlets increases confidence in urgency; asset owners should confirm exposure, patch level, and incident review coverage immediately.
Source: The Hacker News
Signal 06 · BleepingComputer
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers found sandbox escape issues across several AI coding tools where files produced by agents could later be trusted by host-side processes.
Why it matters: Engineering teams should update affected tools, separate agent workspaces from trusted execution paths, and review automation that runs generated files without human approval.
Source: BleepingComputer
Signal 07 · The Hacker News
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
The FakeGit campaign seeded thousands of malicious GitHub repositories, including many posing as AI skills or MCP servers, to distribute SmartLoader malware.
Why it matters: Developers should validate repository reputation, pin dependencies, avoid running unknown setup scripts, and route new AI tooling through security review before adoption.
Source: The Hacker News
Brief sources
Related briefs
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
- MCP Security Testing Checklist
Relevant Loki service: Orvyn — AI agent security private preview.