Dutch Cybersecurity Act: is your organisation secure online? →

Loki Intelligence — Security Briefs · Published

Daily Security Brief: TeamCity, Cisco FMC, OWA, and ICS Exposure

Today's security updates highlight high-impact flaws across CI/CD, perimeter management, webmail, and industrial control environments. Teams should prioritize exposed management planes, validate patch coverage, and pair updates with log review for signs of prior access.

Signal 01 · CISA

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

CISA reports a denial-of-service vulnerability affecting specific Rockwell Automation CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR module versions.

Why it matters: Industrial operators should verify affected firmware, schedule vendor-recommended updates, and ensure control networks limit unnecessary access to controller and communications modules.

Source: CISA

Signal 02 · BleepingComputer

JetBrains warns of critical TeamCity remote code execution flaw

BleepingComputer reports that JetBrains disclosed a critical TeamCity On-Premises authentication bypass that can lead to remote code execution.

Why it matters: TeamCity often has access to source code, build secrets, and deployment paths, so engineering teams should patch quickly, restrict internet exposure, and review recent build server activity.

Source: BleepingComputer

Signal 03 · The Hacker News

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

The Hacker News says Russian-linked actors used a Microsoft Outlook Web Access flaw against government targets to maintain mailbox access even after password changes.

Why it matters: Defenders should treat mail platform compromises as session and persistence events, not just credential theft, and review mailbox access logs, rules, delegated access, and token/session validity.

Source: The Hacker News

Signal 04 · The Hacker News

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The Hacker News reports that CISA added a Cisco Secure Firewall Management Center flaw to its Known Exploited Vulnerabilities catalog after zero-day exploitation activity.

Why it matters: Security teams should prioritize FMC updates, limit access to management interfaces, and review appliance logs and sensitive configuration exposure because firewall managers are high-value control points.

Source: The Hacker News

Signal 05 · CISA

NASA Core Flight System (cFS) Health & Safety (HS) Application

CISA issued an advisory for a denial-of-service issue in NASA's Core Flight System Health & Safety application.

Why it matters: Organizations using cFS components should track affected builds, apply mitigations from maintainers, and validate resilience monitoring so safety-related services fail predictably.

Source: CISA

Signal 06 · CISA

Mitsubishi Electric CC-Link IE TSN Communication Protocol

CISA describes a Mitsubishi Electric CC-Link IE TSN protocol issue that could allow communication data tampering under certain network conditions.

Why it matters: Plant teams should segment industrial Ethernet traffic, restrict untrusted devices on local control segments, and apply vendor guidance to reduce the risk of manipulated process communications.

Source: CISA

Signal 07 · CISA

Schneider Electric IGSS

CISA published an advisory for a vulnerability in Schneider Electric's IGSS Definition module used in its SCADA monitoring and control platform.

Why it matters: Asset owners should identify IGSS deployments, follow Schneider Electric remediation guidance, and harden SCADA workstations with least privilege and controlled project file handling.

Source: CISA

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.