Loki Intelligence — Security Briefs · Published

Daily Security Brief: AI Poisoning, TeamCity Exploits, and Supply Chain Signals

Teams should prioritize internet-facing build systems, software supply chain visibility, and device firmware hygiene while tracking emerging AI and hardware attack paths. Several items point to risks that bypass traditional malware-centric controls, making inventory, patching, monitoring, and policy guardrails especially important.

Signal 01 · The Hacker News

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Researchers describe a prompt-injection pattern that abuses pre-filled AI assistant links on websites to influence downstream AI responses or memory-like behavior. The risk is less about endpoint compromise and more about trust manipulation in AI-assisted browsing and decision workflows.

Why it matters: Product and security teams should review AI deep-link features, sanitize embedded prompts, and treat third-party AI handoff content as untrusted input.

Source: The Hacker News

Signal 02 · The Hacker News

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

CISA added a critical JetBrains TeamCity on-prem vulnerability to its known exploited catalog after reports of active attacks. TeamCity is a high-value target because compromise can expose source code, secrets, build pipelines, and release artifacts.

Why it matters: Engineering and security teams should urgently patch exposed TeamCity instances, review access logs, rotate CI/CD secrets where exposure is possible, and restrict administrative access.

Source: The Hacker News

Signal 03 · GitHub Security

How we took malware advisories beyond npm

GitHub expanded malware advisory coverage beyond npm by integrating malicious-package intelligence from OpenSSF into its Advisory Database. The update is intended to improve ecosystem-wide visibility into package threats across more language communities.

Why it matters: Dependency management programs should consume advisory feeds automatically and validate that tooling covers more than one package registry.

Source: GitHub Security

Signal 04 · CISA

Medixant RadiAnt DICOM

CISA issued a medical advisory for Medixant RadiAnt DICOM versions up to 2025.2, where a crafted DICOM file can crash the application. The issue affects clinical imaging workflows that may depend on application availability.

Why it matters: Healthcare IT teams should update affected viewers, limit handling of untrusted DICOM files, and ensure downtime procedures exist for imaging review systems.

Source: CISA

Signal 05 · CISA

Johnson Controls Inc. TL280

CISA reported an information exposure issue affecting Johnson Controls TL280 devices before version 5.63. The advisory highlights risks in connected alarm and building-security infrastructure.

Why it matters: Facilities and security teams should inventory TL280 deployments, apply vendor updates, and avoid exposing management interfaces to untrusted networks.

Source: CISA

Signal 06 · The Hacker News

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

New research links TeamPCP activity to years of Redis-focused attacks and later supply chain operations. The reporting suggests a long-running actor with experience compromising internet-facing infrastructure before shifting into broader ecosystem abuse.

Why it matters: Teams should harden Redis and similar services, remove public exposure where unnecessary, enforce authentication, and monitor for persistence on cloud and container hosts.

Source: The Hacker News

Signal 07 · BleepingComputer

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers disclosed TONTOU, a speculative execution side-channel technique that challenges some Spectre v2 mitigations and demonstrates leakage risks on Linux systems. The work reinforces that hardware-class weaknesses can persist even after prior mitigation rounds.

Why it matters: Infrastructure teams should track vendor microcode, kernel, and compiler guidance, especially for shared compute, high-sensitivity workloads, and multi-tenant environments.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.