Loki Intelligence — Security Briefs · Published
Daily Security Brief: Customer Data, DDoS, macOS Stealer, AI Outage
Today’s security news highlights operational resilience and identity risk across crypto, secure messaging, AI services, and macOS endpoints. Teams should review breach response workflows, DDoS readiness, third-party dependency plans, and protections against social-engineered malware delivery.
Signal 01 · BleepingComputer
SafePal data breach impacts 39,798 customers, stolen info for sale
SafePal says nearly 40,000 customers were affected after attackers exploited a flaw to access order-related customer information. A threat actor is reportedly offering the stolen data for sale.
Why it matters: Customer order data can fuel phishing, account takeover attempts, and crypto-targeted scams; notify impacted users, monitor impersonation, and harden customer support verification.
Source: BleepingComputer
Signal 02 · BleepingComputer
Anthropic confirms Claude is down in major outage affecting multiple services
Anthropic confirmed a major Claude outage affecting logins and service performance across multiple offerings. The disruption underscores how AI platforms are becoming business-critical dependencies.
Why it matters: Product and engineering teams using AI APIs should define fallback paths, queueing behavior, user messaging, and service-level monitoring for provider outages.
Source: BleepingComputer
Signal 03 · BleepingComputer
Large-scale DDoS attacks disrupted Threema secure messaging service
Threema experienced significant disruption after large-scale DDoS attacks targeted its secure messaging service. Users reportedly faced degraded access during the incident.
Why it matters: Organizations relying on secure messaging should maintain alternate communication channels and validate DDoS mitigation, incident communications, and availability assumptions.
Source: BleepingComputer
Signal 04 · BleepingComputer
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
Researchers reported AmnesiaStealer, a macOS-focused infostealer that targets browser sessions and supports remote interaction with a victim’s browser. The campaign is linked to deceptive user prompts and social engineering.
Why it matters: Security teams should reinforce macOS endpoint controls, browser session protections, employee awareness, and detection for suspicious remote-control and credential access behavior.
Source: BleepingComputer
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.