Loki Intelligence — Security Briefs · Published
Daily Security Brief: TeamCity, Cisco FMC, OWA, and ICS Exposure
Today's security updates highlight high-impact flaws across CI/CD, perimeter management, webmail, and industrial control environments. Teams should prioritize exposed management planes, validate patch coverage, and pair updates with log review for signs of prior access.
Signal 01 · CISA
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
CISA reports a denial-of-service vulnerability affecting specific Rockwell Automation CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR module versions.
Why it matters: Industrial operators should verify affected firmware, schedule vendor-recommended updates, and ensure control networks limit unnecessary access to controller and communications modules.
Source: CISA
Signal 02 · BleepingComputer
JetBrains warns of critical TeamCity remote code execution flaw
BleepingComputer reports that JetBrains disclosed a critical TeamCity On-Premises authentication bypass that can lead to remote code execution.
Why it matters: TeamCity often has access to source code, build secrets, and deployment paths, so engineering teams should patch quickly, restrict internet exposure, and review recent build server activity.
Source: BleepingComputer
Signal 03 · The Hacker News
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Hacker News says Russian-linked actors used a Microsoft Outlook Web Access flaw against government targets to maintain mailbox access even after password changes.
Why it matters: Defenders should treat mail platform compromises as session and persistence events, not just credential theft, and review mailbox access logs, rules, delegated access, and token/session validity.
Source: The Hacker News
Signal 04 · The Hacker News
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News reports that CISA added a Cisco Secure Firewall Management Center flaw to its Known Exploited Vulnerabilities catalog after zero-day exploitation activity.
Why it matters: Security teams should prioritize FMC updates, limit access to management interfaces, and review appliance logs and sensitive configuration exposure because firewall managers are high-value control points.
Source: The Hacker News
Signal 05 · CISA
NASA Core Flight System (cFS) Health & Safety (HS) Application
CISA issued an advisory for a denial-of-service issue in NASA's Core Flight System Health & Safety application.
Why it matters: Organizations using cFS components should track affected builds, apply mitigations from maintainers, and validate resilience monitoring so safety-related services fail predictably.
Source: CISA
Signal 06 · CISA
Mitsubishi Electric CC-Link IE TSN Communication Protocol
CISA describes a Mitsubishi Electric CC-Link IE TSN protocol issue that could allow communication data tampering under certain network conditions.
Why it matters: Plant teams should segment industrial Ethernet traffic, restrict untrusted devices on local control segments, and apply vendor guidance to reduce the risk of manipulated process communications.
Source: CISA
Signal 07 · CISA
Schneider Electric IGSS
CISA published an advisory for a vulnerability in Schneider Electric's IGSS Definition module used in its SCADA monitoring and control platform.
Why it matters: Asset owners should identify IGSS deployments, follow Schneider Electric remediation guidance, and harden SCADA workstations with least privilege and controlled project file handling.
Source: CISA
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.