Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

Daily Brief: Exploited Edge Flaws, CI Risk, and AI Security Moves

Today’s security focus is patch prioritization for internet-facing infrastructure, CI/CD platforms, Linux privilege boundaries, and Windows identity services. Teams should pair urgent remediation with exposure review, certificate-service hardening, and careful evaluation of AI-assisted security claims.

Signal 01 · The Hacker News

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

A researcher reported using AI assistance while developing a local privilege-escalation exploit for a Linux kernel traffic-control race condition affecting a targeted CentOS Stream 9 build.

Why it matters: Treat local kernel flaws as serious in multi-user, container, and shared compute environments; prioritize kernel updates and reduce unnecessary local access paths.

Source: The Hacker News

Signal 02 · The Hacker News

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Attackers are exploiting a critical command-injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments.

Why it matters: Internet-exposed network management systems need rapid patching, restricted admin access, log review, and segmentation because compromise can affect broad infrastructure control.

Source: The Hacker News

Signal 03 · CISA

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added two actively exploited issues to its KEV catalog: a Fortinet FortiOS sensitive-information exposure flaw and the Arista VeloCloud Orchestrator command-injection bug.

Why it matters: Use KEV additions as a remediation trigger for asset owners, especially where affected systems are exposed, externally managed, or tied to privileged network operations.

Source: CISA

Signal 04 · The Hacker News

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

JetBrains warned that on-premises TeamCity installations are affected by a critical flaw that could allow unauthenticated operating-system command execution.

Why it matters: CI servers often hold source code, secrets, and deployment permissions; update quickly, limit network reachability, and rotate credentials if suspicious activity appears.

Source: The Hacker News

Signal 05 · The Hacker News

Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

Microsoft introduced a cybersecurity-focused AI model in its MDASH system and reported improved benchmark performance with lower operating cost.

Why it matters: Security teams should test AI-assisted vulnerability workflows against internal data and quality gates before relying on vendor benchmarks for operational decisions.

Source: The Hacker News

Signal 06 · BleepingComputer

New Certighost PoC exploit lets attackers hijack Windows domains

A public proof of concept was released for Certighost, an Active Directory Certificate Services issue that may let authenticated attackers threaten Windows domain integrity.

Why it matters: Review AD CS exposure, certificate templates, enrollment permissions, and monitoring because certificate abuse can undermine authentication and persistence controls.

Source: BleepingComputer

Signal 07 · The Hacker News

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA and partners launched the Open Secure AI Alliance and released the NOOA framework to advance shared approaches for securing software and AI agents.

Why it matters: Organizations adopting AI agents should track emerging open frameworks, but still require internal threat modeling, permission controls, logging, and deployment governance.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.