Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

Daily Brief: AI Agent Abuse and Internet-Facing RCE Drive Risk

Reports today show AI agents becoming both targets and tools, with risks spanning rogue workspace deployment, unattended post-exploitation, and hallucinated software references. Separately, active exploitation of Java and PLM platforms reinforces the need to prioritize exposed systems and compensating controls when patches lag.

Signal 01 · The Hacker News

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Researchers disclosed a ChatGPT Workspace Agents flaw that could have let an attacker use phishing to create and authorize a rogue agent inside an organization. The issue highlights how agent identity and consent flows can become high-impact security boundaries.

Why it matters: Treat AI agents like privileged applications: review approval workflows, monitor new agent creation, restrict default permissions, and educate users on consent prompts tied to links.

Source: The Hacker News

Signal 02 · The Hacker News

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers are targeting a critical Fastjson 1.x issue affecting some Java Spring Boot environments, with reports indicating no vendor patch is available for the legacy branch. Systems using outdated JSON parsing components may face elevated risk if reachable by untrusted users.

Why it matters: Inventory Fastjson usage, reduce exposure, apply vendor or platform mitigations, add detection around abnormal Java process behavior, and plan migration away from unsupported components.

Source: The Hacker News

Signal 03 · The Hacker News

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p-linked actors are reportedly exploiting internet-facing PTC Windchill and FlexPLM deployments in a new data extortion campaign. The activity focuses on enterprise product lifecycle systems that often hold sensitive engineering and supply chain data.

Why it matters: Prioritize externally exposed PLM assets for patching, access review, segmentation, logging, and rapid investigation of unusual data access or transfer patterns.

Source: The Hacker News

Signal 04 · BleepingComputer

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor allegedly used the open-source Hermes AI agent to automate activity after gaining access to Thailand’s Ministry of Finance environment. The report shows how agentic tools can speed up attacker operations when guardrails are disabled.

Why it matters: Defenders should monitor for unauthorized AI tooling, block risky automation where possible, and enforce approval gates for systems that can execute commands or access sensitive environments.

Source: BleepingComputer

Signal 05 · BleepingComputer

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

The article groups slopsquatting, phantom domains, and HalluSquatting under one pattern: AI systems may suggest non-existent packages, repos, or domains that attackers can later register. This creates a supply chain risk when developers or agents trust generated names without verification.

Why it matters: Use governed dependency management, package allowlists, pre-fetch validation, and repository controls so AI-generated suggestions cannot introduce untrusted code paths.

Source: BleepingComputer

Signal 06 · The Hacker News

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

The piece argues that visibility into AI agents is only an early step, and organizations need enforceable controls over what agents can access and do. Agent sprawl can undermine least privilege if identities, tools, and actions are not governed.

Why it matters: Build policy enforcement for agent permissions, data access, tool use, and approval flows rather than relying only on inventory dashboards or activity logs.

Source: The Hacker News

Signal 07 · The Hacker News

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Additional reporting describes an attacker running Hermes with reduced safety prompts during alleged activity against Thailand’s Ministry of Finance. The case illustrates how widely available AI assistants can be repurposed for hands-off operational support.

Why it matters: Security teams should add AI execution tools to endpoint and cloud detection logic, restrict unmanaged servers, and review whether automation platforms can run without human approval.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki service: Orvyn — AI agent security private preview.