Loki Intelligence — Security Briefs · Published
Daily Security Brief: VMware, GitLab, WordPress, and CI/CD Risks
Today’s brief centers on high-impact vulnerabilities in enterprise infrastructure, developer platforms, WordPress plugins, and CI/CD workflows. Teams should prioritize patch verification, exposure reduction, backup readiness, and monitoring for unusual changes in code, cloud, and identity systems.
Signal 01 · The Hacker News
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Researchers linked active exploitation of a critical VMware vCenter vulnerability to a suspected China-nexus threat actor, with follow-on ransomware activity reportedly using Babuk-derived tooling. The issue affects a core virtualization management layer, raising the potential impact across enterprise environments.
Why it matters: Treat vCenter as Tier 0 infrastructure: patch quickly, restrict management access, review admin activity, and validate offline backups for virtualization workloads.
Source: The Hacker News
Signal 02 · CISA
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2025-62593, a Ray code injection vulnerability, to its Known Exploited Vulnerabilities catalog after evidence of active abuse. KEV additions indicate defenders should move beyond routine prioritization and assume real-world attacker interest.
Why it matters: Inventory Ray deployments, apply vendor guidance, limit external exposure, and use the KEV catalog as a trigger for expedited remediation SLAs.
Source: CISA
Signal 03 · The Hacker News
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Researchers disclosed a GitHub Actions workflow injection issue in Snowflake’s public connector repository that could be triggered through crafted issue content and expose internal automation secrets. The case underscores how community-facing workflows can become a bridge into trusted engineering systems.
Why it matters: Review CI/CD workflows that process user-controlled content, minimize secret availability in automation, and require least-privilege tokens for public repository jobs.
Source: The Hacker News
Signal 04 · The Hacker News
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical flaw in the Forminator WordPress plugin could allow unauthenticated code execution on vulnerable sites through unsafe file handling. With more than 600,000 installations, the affected plugin has a large potential exposure window.
Why it matters: Update the plugin immediately, audit uploaded files, monitor web server behavior, and consider blocking direct execution from upload directories.
Source: The Hacker News
Signal 05 · BleepingComputer
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft confirmed it is preparing a Defender fix for the ShieldBreak zero-day, now tracked as CVE-2026-69414. Until a patch is available, affected environments may need compensating controls and heightened endpoint monitoring.
Why it matters: Track Microsoft advisories, verify Defender health and telemetry coverage, and layer endpoint controls so detection does not depend on a single protection component.
Source: BleepingComputer
Signal 06 · The Hacker News
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab released security updates for a critical GraphQL vulnerability that could allow unauthenticated remote modification or deletion of public projects and user data under certain conditions. The flaw affects both Community Edition and Enterprise Edition deployments.
Why it matters: Patch self-managed GitLab quickly, review public project permissions, monitor for unexpected repository changes, and confirm restore procedures for critical code assets.
Source: The Hacker News
Signal 07 · BleepingComputer
Microsoft confirms GitHub is down worldwide
Microsoft confirmed a broad GitHub outage affecting services including the website, API, Actions, and pull requests for some users. The disruption highlights operational dependencies on centralized development platforms.
Why it matters: Build contingency plans for source control and CI/CD outages, cache critical dependencies, and define release hold or failover procedures for engineering teams.
Source: BleepingComputer
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.