Loki Intelligence — Security Briefs · Published
Daily Security Brief: Exploited CVEs, AI Agent Risk, and Industrial Software Flaws
CISA and security researchers reported multiple actively exploited vulnerabilities affecting Microsoft, Broadcom, MLflow, Windows, and industrial software. Teams should prioritize KEV-driven remediation, tighten exposure of AI and OT systems, and watch for data-theft activity against engineering platforms.
Signal 01 · CISA
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including issues affecting Microsoft IKE, Microsoft SharePoint, and Broadcom products.
Why it matters: Use the KEV update to drive urgent patch prioritization, asset discovery, and compensating controls for internet-facing or high-value systems.
Source: CISA
Signal 02 · The Hacker News
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Researchers observed exploitation and scanning tied to critical flaws in MLflow and FUXA, with MLflow abuse focused on reaching cloud metadata and secrets.
Why it matters: Restrict public access to AI and OT management tools, rotate exposed credentials, and monitor cloud identity activity for unusual token use.
Source: The Hacker News
Signal 03 · The Hacker News
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
Researchers demonstrated that autonomous AI agents can pass harmful instructions between systems through persistent prompt or state files.
Why it matters: Treat agent memory and prompt files as sensitive inputs: validate, isolate, version, and monitor them like executable configuration.
Source: The Hacker News
Signal 04 · BleepingComputer
CISA: Windows Task Host flaw now exploited by ransomware gangs
CISA confirmed that ransomware operators are exploiting a high-severity Windows Task Host vulnerability previously flagged as under active attack.
Why it matters: Ensure Windows endpoints are fully updated and use EDR detections for suspicious task execution, privilege abuse, and ransomware staging behavior.
Source: BleepingComputer
Signal 05 · CISA
Siemens Simcenter Nastran
CISA warned that Siemens Simcenter Nastran is affected by a stack overflow issue that can be triggered through crafted file handling.
Why it matters: Engineering workstations should receive vendor updates, limit untrusted files, and run simulation tools with least privilege where practical.
Source: CISA
Signal 06 · CISA
CISA Malcolm
CISA published an advisory for multiple Malcolm vulnerabilities that may enable denial of service or code execution in affected versions.
Why it matters: Update Malcolm deployments promptly and review monitoring infrastructure exposure, since defensive tools can become high-impact targets.
Source: CISA
Signal 07 · BleepingComputer
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell linked to Clop activity appears tailored for PTC Windchill and FlexPLM environments to support credential access and file theft.
Why it matters: Organizations using product lifecycle platforms should hunt for unauthorized web components, review repository access logs, and strengthen segmentation around design data.
Source: BleepingComputer
Brief sources
Related briefs
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
- MCP Security Testing Checklist
Relevant Loki service: Orvyn — AI agent security private preview.