Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

Daily Security Brief: AI Agent Escapes, Zimbra Abuse, and Linux Priv-Esc

Security teams should prioritize patch validation across internet-facing collaboration tools, Linux systems, and operational technology platforms. AI-enabled products also need stronger sandboxing, prompt-handling controls, and abuse-focused testing before deployment.

Signal 01 · The Hacker News

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Researchers reported a sandbox escape issue in Anthropic’s Claude Cowork that could allow an AI agent running in a Linux VM to interact with files on the host Mac. The finding highlights how agentic tooling can create new boundary and data exposure risks.

Why it matters: Treat AI agent runtimes as high-risk execution environments: enforce host isolation, least-privilege file access, monitoring, and rapid update processes for AI desktop tools.

Source: The Hacker News

Signal 02 · The Hacker News

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

NodeBB patched eight high-severity vulnerabilities found during an AI-assisted security review, with reported impact including admin access exposure and private chat compromise. Public disclosure increases urgency for operators running affected versions.

Why it matters: Engineering teams should upgrade promptly, review forum permissions, rotate sensitive credentials if exposure is suspected, and monitor for unusual admin or messaging activity.

Source: The Hacker News

Signal 03 · BleepingComputer

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA warned that the Russian state-linked group Laundry Bear, also known as Void Blizzard, is targeting Zimbra Collaboration servers using phishing and a patched zero-click vulnerability. The activity is focused on email access and theft.

Why it matters: Organizations using Zimbra should confirm patch status, harden mail access, review mailbox rules and authentication logs, and strengthen phishing-resistant MFA.

Source: BleepingComputer

Signal 04 · The Hacker News

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

This week’s threat roundup points to malicious packages, fake browser extensions, spyware disguised as useful apps, AI prompt-injection risks, and exposed industrial systems. The common pattern is trusted-looking functionality hiding malicious behavior.

Why it matters: Security teams should expand supply chain checks, restrict extension installation, vet mobile apps, and include AI prompt-injection scenarios in product threat models.

Source: The Hacker News

Signal 05 · BleepingComputer

New RefluXFS Linux flaw lets attackers gain root privileges

A long-standing race condition in the Linux kernel XFS filesystem, tracked as CVE-2026-64600, can allow local privilege escalation on affected systems. The issue is notable because XFS is widely used in server environments.

Why it matters: Prioritize kernel updates for Linux fleets, especially multi-user servers and container hosts, and monitor for signs of local privilege escalation attempts.

Source: BleepingComputer

Signal 06 · CISA

Rockwell Automation ThinManager

CISA published an advisory for Rockwell Automation ThinManager affecting several 13.x versions, where authenticated misuse could write files outside intended application directories. Fixed versions are available for the impacted release branches.

Why it matters: OT teams should update affected ThinManager deployments, limit authenticated access, segment management systems, and watch for unexpected file changes in restricted paths.

Source: CISA

Signal 07 · CISA

Johnson Controls XAAP Android

CISA warned of a Johnson Controls XAAP Android issue affecting versions before 1.53 that could expose confidential information from the device. The advisory assigns a low CVSS score but still recommends remediation.

Why it matters: Organizations using XAAP Android should update to the vendor-fixed version and review mobile device handling, data minimization, and physical access controls.

Source: CISA

Brief sources

Related briefs

Relevant Loki service: Orvyn — AI agent security private preview.