Loki Intelligence — Security Briefs · Published

Daily Security Brief: SharePoint, vCenter, ICS flaws, and AI trust risks

Attackers are moving quickly on newly disclosed enterprise vulnerabilities, with SharePoint and VMware vCenter both seeing exploitation activity after public disclosure or patch availability. Industrial operators should also review fresh CISA advisories, while software teams can use open source security lessons to harden AI-era development workflows.

Signal 01 · The Hacker News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are exploiting a critical Microsoft SharePoint authentication bypass after public proof-of-concept details became available. The issue has a high severity rating and affects a widely deployed collaboration platform.

Why it matters: Prioritize SharePoint patch validation, restrict external exposure where possible, and monitor authentication anomalies, new web-accessible files, and unexpected privilege changes.

Source: The Hacker News

Signal 02 · CISA

Haiwell IoT Cloud HMI Gateway

CISA warned that Haiwell IoT Cloud HMI Gateway contains a vulnerability that could allow command execution with elevated system privileges. The affected gateway is used in industrial environments, increasing potential operational impact.

Why it matters: Asset owners should identify exposed Haiwell gateways, apply vendor fixes or mitigations, and isolate HMI management interfaces from untrusted networks.

Source: CISA

Signal 03 · GitHub Security

What 50 open source projects taught us about security in the AI era

GitHub shared lessons from 50 open source projects that improved security using AI-assisted workflows, maintainer knowledge, platform tooling, expert support, and funding. The post highlights that AI can help, but does not replace structured security practices.

Why it matters: Engineering teams should pair AI coding and review tools with dependency scanning, secret detection, maintainer education, and human review for high-risk changes.

Source: GitHub Security

Signal 04 · CISA

AVEVA Enterprise SCADA

CISA published an advisory for AVEVA Enterprise SCADA involving unsafe serialized data handling that could lead to code execution. Multiple Enterprise SCADA versions are listed as affected.

Why it matters: SCADA administrators should review affected versions, plan upgrades, and limit access to systems that process serialized data or project files from untrusted sources.

Source: CISA

Signal 05 · BleepingComputer

AI 'watermark removers' flood the web. Almost none can prove they work.

BleepingComputer reported a surge of tools and services claiming to remove AI text watermarks after Anthropic introduced watermarking for Claude outputs. The article notes that most claims lack reliable evidence.

Why it matters: Security and product teams should avoid relying on watermarking alone for provenance decisions and should combine policy, metadata, detection, and user-risk signals.

Source: BleepingComputer

Signal 06 · BleepingComputer

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical VMware vCenter Syslog Server vulnerability is reportedly being exploited to establish persistent remote access. The flaw was recently patched, but active campaigns show a short window between disclosure and abuse.

Why it matters: Patch vCenter quickly, review internet exposure, audit unusual outbound SSH activity, and check administrative appliances for unauthorized persistence mechanisms.

Source: BleepingComputer

Signal 07 · CISA

Siemens Parasolid

CISA disclosed a Siemens Parasolid vulnerability triggered by processing X_T files, with possible outcomes including application crash or code execution. Siemens has released guidance for affected users.

Why it matters: Organizations using Parasolid-based workflows should update affected software and treat externally supplied CAD files as untrusted content requiring screening and isolation.

Source: CISA

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.