Loki Intelligence — Security Briefs · Published

Daily Security Brief: KEV Updates, CMS Risk, CI Secrets, and Supply Chain Malware

Today’s security news centers on active exploitation, including a new CISA KEV entry, Metabase data theft, and a WordPress flaw with serious downstream impact. Teams should prioritize exposed systems, tighten CI and package controls, and review identity protections where endpoint compromise could extend into cloud access.

Signal 01 · CISA

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-8037, a Progress LoadMaster command injection issue, to its Known Exploited Vulnerabilities catalog after observing active exploitation.

Why it matters: Treat internet-facing load balancing and application delivery systems as high priority for patching, exposure review, and compromise checks.

Source: CISA

Signal 02 · The Hacker News

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress patched a pre-authentication reflected XSS issue affecting the login page across versions, with researchers showing it could be combined with other conditions for server-side impact.

Why it matters: Update WordPress quickly, reduce unnecessary plugin and theme risk, and monitor authentication pages for unusual traffic or injected content.

Source: The Hacker News

Signal 03 · The Hacker News

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Researchers found weaknesses in AI coding-agent workflows that allowed low-privilege GitHub issue activity to influence CI execution and potentially expose workflow secrets.

Why it matters: Review agent permissions, isolate CI secrets, restrict untrusted issue-triggered automation, and require human approval for sensitive workflow actions.

Source: The Hacker News

Signal 04 · BleepingComputer

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection zero-day was reportedly exploited against customer instances, with Framework and Tally disclosing data-theft incidents.

Why it matters: Patch Metabase immediately, rotate exposed credentials, review database access logs, and validate whether analytics tools have broader data access than needed.

Source: BleepingComputer

Signal 05 · The Hacker News

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 malicious npm packages were published in a campaign delivering cross-platform remote access and information-stealing malware to Windows, macOS, and Linux users.

Why it matters: Strengthen dependency review, pin trusted packages, scan lockfiles and developer endpoints, and watch for typosquatting or AI-generated package names.

Source: The Hacker News

Signal 06 · The Hacker News

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger reported that an AI-assisted research system identified new HTTP desynchronization techniques, while related research also uncovered an Apache zero-day.

Why it matters: Keep web servers, proxies, and application gateways updated, and test request-handling behavior across layered infrastructure after changes.

Source: The Hacker News

Signal 07 · The Hacker News

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Research showed malware running in an active Windows session could use Windows Hello for Business keys to authenticate to Microsoft Entra ID and support longer-lived cloud access.

Why it matters: Harden endpoints, monitor unusual Entra ID registrations and token activity, and combine phishing-resistant authentication with strong device health controls.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.