Loki Intelligence — Security Briefs · Published
Daily Security Brief: KEV Updates, CMS Risk, CI Secrets, and Supply Chain Malware
Today’s security news centers on active exploitation, including a new CISA KEV entry, Metabase data theft, and a WordPress flaw with serious downstream impact. Teams should prioritize exposed systems, tighten CI and package controls, and review identity protections where endpoint compromise could extend into cloud access.
Signal 01 · CISA
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2026-8037, a Progress LoadMaster command injection issue, to its Known Exploited Vulnerabilities catalog after observing active exploitation.
Why it matters: Treat internet-facing load balancing and application delivery systems as high priority for patching, exposure review, and compromise checks.
Source: CISA
Signal 02 · The Hacker News
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress patched a pre-authentication reflected XSS issue affecting the login page across versions, with researchers showing it could be combined with other conditions for server-side impact.
Why it matters: Update WordPress quickly, reduce unnecessary plugin and theme risk, and monitor authentication pages for unusual traffic or injected content.
Source: The Hacker News
Signal 03 · The Hacker News
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Researchers found weaknesses in AI coding-agent workflows that allowed low-privilege GitHub issue activity to influence CI execution and potentially expose workflow secrets.
Why it matters: Review agent permissions, isolate CI secrets, restrict untrusted issue-triggered automation, and require human approval for sensitive workflow actions.
Source: The Hacker News
Signal 04 · BleepingComputer
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical Metabase SQL injection zero-day was reportedly exploited against customer instances, with Framework and Tally disclosing data-theft incidents.
Why it matters: Patch Metabase immediately, rotate exposed credentials, review database access logs, and validate whether analytics tools have broader data access than needed.
Source: BleepingComputer
Signal 05 · The Hacker News
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Nearly 800 malicious npm packages were published in a campaign delivering cross-platform remote access and information-stealing malware to Windows, macOS, and Linux users.
Why it matters: Strengthen dependency review, pin trusted packages, scan lockfiles and developer endpoints, and watch for typosquatting or AI-generated package names.
Source: The Hacker News
Signal 06 · The Hacker News
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger reported that an AI-assisted research system identified new HTTP desynchronization techniques, while related research also uncovered an Apache zero-day.
Why it matters: Keep web servers, proxies, and application gateways updated, and test request-handling behavior across layered infrastructure after changes.
Source: The Hacker News
Signal 07 · The Hacker News
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Research showed malware running in an active Windows session could use Windows Hello for Business keys to authenticate to Microsoft Entra ID and support longer-lived cloud access.
Why it matters: Harden endpoints, monitor unusual Entra ID registrations and token activity, and combine phishing-resistant authentication with strong device health controls.
Source: The Hacker News
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.