Loki Intelligence — Security Briefs · Published
Daily Security Brief: SharePoint, vCenter, ICS flaws, and AI trust risks
Attackers are moving quickly on newly disclosed enterprise vulnerabilities, with SharePoint and VMware vCenter both seeing exploitation activity after public disclosure or patch availability. Industrial operators should also review fresh CISA advisories, while software teams can use open source security lessons to harden AI-era development workflows.
Signal 01 · The Hacker News
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are exploiting a critical Microsoft SharePoint authentication bypass after public proof-of-concept details became available. The issue has a high severity rating and affects a widely deployed collaboration platform.
Why it matters: Prioritize SharePoint patch validation, restrict external exposure where possible, and monitor authentication anomalies, new web-accessible files, and unexpected privilege changes.
Source: The Hacker News
Signal 02 · CISA
Haiwell IoT Cloud HMI Gateway
CISA warned that Haiwell IoT Cloud HMI Gateway contains a vulnerability that could allow command execution with elevated system privileges. The affected gateway is used in industrial environments, increasing potential operational impact.
Why it matters: Asset owners should identify exposed Haiwell gateways, apply vendor fixes or mitigations, and isolate HMI management interfaces from untrusted networks.
Source: CISA
Signal 03 · GitHub Security
What 50 open source projects taught us about security in the AI era
GitHub shared lessons from 50 open source projects that improved security using AI-assisted workflows, maintainer knowledge, platform tooling, expert support, and funding. The post highlights that AI can help, but does not replace structured security practices.
Why it matters: Engineering teams should pair AI coding and review tools with dependency scanning, secret detection, maintainer education, and human review for high-risk changes.
Source: GitHub Security
Signal 04 · CISA
AVEVA Enterprise SCADA
CISA published an advisory for AVEVA Enterprise SCADA involving unsafe serialized data handling that could lead to code execution. Multiple Enterprise SCADA versions are listed as affected.
Why it matters: SCADA administrators should review affected versions, plan upgrades, and limit access to systems that process serialized data or project files from untrusted sources.
Source: CISA
Signal 05 · BleepingComputer
AI 'watermark removers' flood the web. Almost none can prove they work.
BleepingComputer reported a surge of tools and services claiming to remove AI text watermarks after Anthropic introduced watermarking for Claude outputs. The article notes that most claims lack reliable evidence.
Why it matters: Security and product teams should avoid relying on watermarking alone for provenance decisions and should combine policy, metadata, detection, and user-risk signals.
Source: BleepingComputer
Signal 06 · BleepingComputer
Critical VMware vCenter RCE flaw exploited for reverse SSH access
A critical VMware vCenter Syslog Server vulnerability is reportedly being exploited to establish persistent remote access. The flaw was recently patched, but active campaigns show a short window between disclosure and abuse.
Why it matters: Patch vCenter quickly, review internet exposure, audit unusual outbound SSH activity, and check administrative appliances for unauthorized persistence mechanisms.
Source: BleepingComputer
Signal 07 · CISA
Siemens Parasolid
CISA disclosed a Siemens Parasolid vulnerability triggered by processing X_T files, with possible outcomes including application crash or code execution. Siemens has released guidance for affected users.
Why it matters: Organizations using Parasolid-based workflows should update affected software and treat externally supplied CAD files as untrusted content requiring screening and isolation.
Source: CISA
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.