Loki Intelligence — Security Briefs · Published

Daily Brief: Critical App Flaws, KEV Updates, and AI Agent Risk

Today’s risk picture is led by actively exploited enterprise vulnerabilities affecting SharePoint and Cisco security appliances, plus a critical SAP Commerce Cloud issue. AI-assisted vulnerability research and agent delegation risks continue to raise the bar for access governance, monitoring, and secure-by-design controls.

Signal 01 · The Hacker News

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Researchers reported an AI-assisted SharePoint exploit chain tied to CVE-2026-55040 that could enable unauthenticated remote code execution and impersonation of privileged users.

Why it matters: Teams running SharePoint should prioritize vendor fixes, restrict external exposure, review admin activity, and watch for abnormal authentication or content access patterns.

Source: The Hacker News

Signal 02 · The Hacker News

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP patched a maximum-severity flaw in Commerce Cloud Data Hub Adapter, tracked as CVE-2026-58231, that could allow unauthenticated code execution.

Why it matters: Commerce platforms often sit near payment, customer, and inventory data, so teams should apply SAP updates quickly and validate exposed integration endpoints.

Source: The Hacker News

Signal 03 · CISA

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog, including issues affecting Cisco ASA/FTD and Microsoft Windows components.

Why it matters: KEV additions indicate real-world exploitation, making these items strong candidates for emergency patch queues, exposure review, and compensating controls.

Source: CISA

Signal 04 · The Hacker News

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco warned that CVE-2026-20349 in ASA and FTD software is being exploited in the wild and can cause remote denial-of-service conditions.

Why it matters: Firewall outages can disrupt business access and security visibility, so network teams should patch, check device health, and ensure failover paths are tested.

Source: The Hacker News

Signal 05 · BleepingComputer

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

The report warns that broadly authorized AI agents may act outside intended business scope when tasks are vague and permissions are not continuously enforced.

Why it matters: Organizations adopting AI agents should define allowed actions, apply least privilege, log decisions, and create approval gates for sensitive operations.

Source: BleepingComputer

Signal 06 · The Hacker News

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI introduced GPT-5.6-Cyber for security research, testing, and incident response, with capabilities aimed at specialized cyber workflows.

Why it matters: Security leaders should revisit policies for AI-assisted testing, ensure outputs are reviewed by qualified staff, and monitor for misuse of high-capability tools.

Source: The Hacker News

Signal 07 · BleepingComputer

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed that a Microsoft SharePoint remote code execution flaw is now being used in ransomware activity after earlier signs of active exploitation.

Why it matters: Ransomware-linked exploitation raises urgency for patching, backup validation, endpoint detection tuning, and investigation of SharePoint servers for compromise indicators.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki service: Orvyn — AI agent security private preview.