Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

Daily Brief: Ransomware, SharePoint, WordPress, and AI Agent Risk

Attackers are rapidly operationalizing recently disclosed flaws across PAN-OS, SharePoint, WordPress, Langflow, and industrial applications. Teams should prioritize exposed-system patching, post-compromise checks, credential rotation, and tighter controls around AI coding agents.

Signal 01 · The Hacker News

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Qilin ransomware operators reportedly used a patched PAN-OS authentication bypass as an entry point in multiple intrusions. The activity shows continued targeting of internet-facing security appliances for initial access.

Why it matters: Confirm PAN-OS patches are deployed, review firewall logs for suspicious authentication activity, and validate that appliance compromise is included in ransomware response playbooks.

Source: The Hacker News

Signal 02 · The Hacker News

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers observed ENCFORGE, a new Go-based ransomware, deployed against a Langflow environment and designed to target AI model-related files. The activity is linked to an operator previously associated with AI-agent-driven attacks.

Why it matters: Treat AI workflow servers as production assets: patch Langflow, restrict network exposure, back up model artifacts, and monitor for unusual file changes or encryption activity.

Source: The Hacker News

Signal 03 · CISA

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA added four actively exploited vulnerabilities to its KEV catalog, including issues affecting DD-WRT, Langflow, WordPress Core, and another listed product. KEV additions indicate verified exploitation in the wild.

Why it matters: Use KEV status to drive emergency remediation, especially for internet-facing systems and platforms that support content management, AI workflows, or network access.

Source: CISA

Signal 04 · CISA

Siemens Opcenter X

CISA warned that Siemens Opcenter X versions before V2604 contain an authentication bypass that could allow unauthorized application access. Siemens has released an updated version to address the issue.

Why it matters: Industrial and manufacturing teams should update affected Opcenter X deployments, review access logs, and ensure business-critical production systems are segmented from broader enterprise networks.

Source: CISA

Signal 05 · The Hacker News

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A flaw involving Azure DevOps MCP workflows could allow hidden pull request content to influence AI review agents and expose data beyond the attacker’s normal access. The issue highlights risks from agentic tooling connected to source repositories.

Why it matters: Limit AI agent permissions, isolate repository scopes, review third-party MCP integrations, and require human approval before agents access sensitive projects or external resources.

Source: The Hacker News

Signal 06 · BleepingComputer

Critical SharePoint RCE flaw exploited to steal machine keys

Attackers are exploiting a critical SharePoint remote code execution flaw to steal machine keys, enabling persistence that may survive basic patching. Compromised keys can undermine trust assumptions inside affected SharePoint environments.

Why it matters: Patch immediately, rotate exposed machine keys, inspect servers for persistence, and assume remediation may require more than applying the vendor update.

Source: BleepingComputer

Signal 07 · BleepingComputer

Critical wp2shell WordPress flaws exploited to install webshells

Critical WordPress Core vulnerabilities known as wp2shell are being exploited to place webshells and malicious plugins on affected sites. The activity creates durable access for follow-on abuse such as spam, credential theft, or lateral movement.

Why it matters: Update WordPress quickly, audit plugins and themes, scan for unauthorized files, and rotate administrative credentials after any suspected compromise.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki service: Orvyn — AI agent security private preview.