Loki Intelligence — Security Briefs · Published
Daily Brief: AI Agent Abuse and Internet-Facing RCE Drive Risk
Reports today show AI agents becoming both targets and tools, with risks spanning rogue workspace deployment, unattended post-exploitation, and hallucinated software references. Separately, active exploitation of Java and PLM platforms reinforces the need to prioritize exposed systems and compensating controls when patches lag.
Signal 01 · The Hacker News
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Researchers disclosed a ChatGPT Workspace Agents flaw that could have let an attacker use phishing to create and authorize a rogue agent inside an organization. The issue highlights how agent identity and consent flows can become high-impact security boundaries.
Why it matters: Treat AI agents like privileged applications: review approval workflows, monitor new agent creation, restrict default permissions, and educate users on consent prompts tied to links.
Source: The Hacker News
Signal 02 · The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are targeting a critical Fastjson 1.x issue affecting some Java Spring Boot environments, with reports indicating no vendor patch is available for the legacy branch. Systems using outdated JSON parsing components may face elevated risk if reachable by untrusted users.
Why it matters: Inventory Fastjson usage, reduce exposure, apply vendor or platform mitigations, add detection around abnormal Java process behavior, and plan migration away from unsupported components.
Source: The Hacker News
Signal 03 · The Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p-linked actors are reportedly exploiting internet-facing PTC Windchill and FlexPLM deployments in a new data extortion campaign. The activity focuses on enterprise product lifecycle systems that often hold sensitive engineering and supply chain data.
Why it matters: Prioritize externally exposed PLM assets for patching, access review, segmentation, logging, and rapid investigation of unusual data access or transfer patterns.
Source: The Hacker News
Signal 04 · BleepingComputer
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor allegedly used the open-source Hermes AI agent to automate activity after gaining access to Thailand’s Ministry of Finance environment. The report shows how agentic tools can speed up attacker operations when guardrails are disabled.
Why it matters: Defenders should monitor for unauthorized AI tooling, block risky automation where possible, and enforce approval gates for systems that can execute commands or access sensitive environments.
Source: BleepingComputer
Signal 05 · BleepingComputer
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
The article groups slopsquatting, phantom domains, and HalluSquatting under one pattern: AI systems may suggest non-existent packages, repos, or domains that attackers can later register. This creates a supply chain risk when developers or agents trust generated names without verification.
Why it matters: Use governed dependency management, package allowlists, pre-fetch validation, and repository controls so AI-generated suggestions cannot introduce untrusted code paths.
Source: BleepingComputer
Signal 06 · The Hacker News
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
The piece argues that visibility into AI agents is only an early step, and organizations need enforceable controls over what agents can access and do. Agent sprawl can undermine least privilege if identities, tools, and actions are not governed.
Why it matters: Build policy enforcement for agent permissions, data access, tool use, and approval flows rather than relying only on inventory dashboards or activity logs.
Source: The Hacker News
Signal 07 · The Hacker News
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Additional reporting describes an attacker running Hermes with reduced safety prompts during alleged activity against Thailand’s Ministry of Finance. The case illustrates how widely available AI assistants can be repurposed for hands-off operational support.
Why it matters: Security teams should add AI execution tools to endpoint and cloud detection logic, restrict unmanaged servers, and review whether automation platforms can run without human approval.
Source: The Hacker News
Brief sources
Related briefs
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
- MCP Security Testing Checklist
Relevant Loki service: Orvyn — AI agent security private preview.