Loki Intelligence — Security Briefs · Published

Daily Security Brief: VMware, GitLab, WordPress, and CI/CD Risks

Today’s brief centers on high-impact vulnerabilities in enterprise infrastructure, developer platforms, WordPress plugins, and CI/CD workflows. Teams should prioritize patch verification, exposure reduction, backup readiness, and monitoring for unusual changes in code, cloud, and identity systems.

Signal 01 · The Hacker News

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Researchers linked active exploitation of a critical VMware vCenter vulnerability to a suspected China-nexus threat actor, with follow-on ransomware activity reportedly using Babuk-derived tooling. The issue affects a core virtualization management layer, raising the potential impact across enterprise environments.

Why it matters: Treat vCenter as Tier 0 infrastructure: patch quickly, restrict management access, review admin activity, and validate offline backups for virtualization workloads.

Source: The Hacker News

Signal 02 · CISA

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2025-62593, a Ray code injection vulnerability, to its Known Exploited Vulnerabilities catalog after evidence of active abuse. KEV additions indicate defenders should move beyond routine prioritization and assume real-world attacker interest.

Why it matters: Inventory Ray deployments, apply vendor guidance, limit external exposure, and use the KEV catalog as a trigger for expedited remediation SLAs.

Source: CISA

Signal 03 · The Hacker News

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Researchers disclosed a GitHub Actions workflow injection issue in Snowflake’s public connector repository that could be triggered through crafted issue content and expose internal automation secrets. The case underscores how community-facing workflows can become a bridge into trusted engineering systems.

Why it matters: Review CI/CD workflows that process user-controlled content, minimize secret availability in automation, and require least-privilege tokens for public repository jobs.

Source: The Hacker News

Signal 04 · The Hacker News

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical flaw in the Forminator WordPress plugin could allow unauthenticated code execution on vulnerable sites through unsafe file handling. With more than 600,000 installations, the affected plugin has a large potential exposure window.

Why it matters: Update the plugin immediately, audit uploaded files, monitor web server behavior, and consider blocking direct execution from upload directories.

Source: The Hacker News

Signal 05 · BleepingComputer

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft confirmed it is preparing a Defender fix for the ShieldBreak zero-day, now tracked as CVE-2026-69414. Until a patch is available, affected environments may need compensating controls and heightened endpoint monitoring.

Why it matters: Track Microsoft advisories, verify Defender health and telemetry coverage, and layer endpoint controls so detection does not depend on a single protection component.

Source: BleepingComputer

Signal 06 · The Hacker News

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab released security updates for a critical GraphQL vulnerability that could allow unauthenticated remote modification or deletion of public projects and user data under certain conditions. The flaw affects both Community Edition and Enterprise Edition deployments.

Why it matters: Patch self-managed GitLab quickly, review public project permissions, monitor for unexpected repository changes, and confirm restore procedures for critical code assets.

Source: The Hacker News

Signal 07 · BleepingComputer

Microsoft confirms GitHub is down worldwide

Microsoft confirmed a broad GitHub outage affecting services including the website, API, Actions, and pull requests for some users. The disruption highlights operational dependencies on centralized development platforms.

Why it matters: Build contingency plans for source control and CI/CD outages, cache critical dependencies, and define release hold or failover procedures for engineering teams.

Source: BleepingComputer

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.